Might also be possible to confirm with pfctl -d / test traceroute / pfctl -e as a quick test that pf is doing it.
You can revert the kernel as suggested.
@doktornotor Are you using Xen?
Now, this crafted ping packets nonsense reminds me of this rant I wrote almost 20 years ago.
@doktornotorhttp://www.ranum.com/security/computer_security/papers/a1-firewall/index.html
@doktornotor# opnsense-update -zkr 24.7-xen3I'll leave it there for a while longer then.
Jokes aside this should probably be reported to https://bugs.freebsd.org but at this point I have no hopes somebody even cares giving the number of past and pending issues in that general direction.
# opnsense-update -zkr 24.7-xen3I'll leave it there for a while longer then.
@doktornotor# opnsense-update -zkr 24.7-xen3I'll leave it there for a while longer then.Cheers,Franco