OS X 10.10 Support

2,042 views
Skip to first unread message

jd.ang...@gmail.com

unread,
Aug 21, 2014, 11:48:59 AM8/21/14
to sshu...@googlegroups.com
Hello,

If I'm not mistaken, neither iptables nor ipfw is included in OS X 10.10 "Yosemite."  I'm on the beta currently and sshuttle is clearly broken.  Are there any plans to support future OS versions?  Anything I can do currently to get sshuttle up and running?  

Apologies for the fairly vague question.
Best,

JDA

Avery Pennarun

unread,
Aug 21, 2014, 1:05:21 PM8/21/14
to jd.ang...@gmail.com, sshuttle mailing list
I don't know how 10.10 works and I'm unlikely to get it until some
time after the final release, as I tend to avoid betas.

The "right" answer is probably to switch from ipfw to pf.

The actual firewalling code in sshuttle is pretty small, so if you (or
someone reading this) are familiar with pf, maybe you can try hacking
it up and submitting a patch. ipfw has been half-broken in MacOS X
for several releases now so it would probably be an overall net
benefit.
> --
> You received this message because you are subscribed to the Google Groups
> "sshuttle" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to sshuttle+u...@googlegroups.com.
> For more options, visit https://groups.google.com/d/optout.

abdussel...@gmail.com

unread,
Oct 17, 2014, 1:39:35 PM10/17/14
to sshu...@googlegroups.com, jd.ang...@gmail.com
Since 10.10 officially released, any plans on implementing the change to pf ?

dr...@drewworthey.com

unread,
Oct 22, 2014, 3:59:43 PM10/22/14
to sshu...@googlegroups.com, jd.ang...@gmail.com, abdussel...@gmail.com
I've started working on this a little bit. Will have more updates soon.

and...@andrewwade.co.uk

unread,
Oct 26, 2014, 9:58:51 AM10/26/14
to sshu...@googlegroups.com, jd.ang...@gmail.com, abdussel...@gmail.com, dr...@drewworthey.com
Hey,

I too am interested in getting sshuttle working with pf(ctl). I know Python but not so much about OS X systems programming nor PF.

What's the best way to move forward (collaboratively)? Is this the best place to track progress or could we open a ticket/issue somewhere?

Regards.

Drew Worthey

unread,
Oct 26, 2014, 11:50:44 AM10/26/14
to and...@andrewwade.co.uk, sshu...@googlegroups.com, jd.ang...@gmail.com, abdussel...@gmail.com
Let's move the conversation to my fork: https://github.com/zabracks/sshuttle

I set up an issues board for the repo there and committed the little I've been able to work on. I'm in the same boat as you -- know python, but have to do my reading on pf.

msm...@instructure.com

unread,
Nov 14, 2014, 11:35:29 AM11/14/14
to sshu...@googlegroups.com, and...@andrewwade.co.uk, jd.ang...@gmail.com, abdussel...@gmail.com, dr...@drewworthey.com
FWIW 

http://stackoverflow.com/questions/25873329/using-packetfilter-to-transparently-proxy-packets-in-os-x

If someone can solve this I think we can get sshuttle working.

Reply all
Reply to author
Forward
0 new messages