Hallo Misc !

I have a problem with the Pf.

I dont understand why but for some reason it wont let ports 80 - 15352 pass
even though I have set it up n the configuration. Its been done according to
the faq and pfctl -nf doesnt return any errors at all !!!
Also NAT in the internal network and all communications from the int:if to
the openbsd are fine !

I am pasting below the conf so you can tell me if you see something wrong.
Thank you for your time !

Best Regards

int_if = "rl0"
ext_if = "tun0"
core = ""
giouli = ""
lydia = ""
icall = ""
laptop = ""
wifi = ""
clients = "{" $core $giouli $lydia $icall $laptop $wifi "}"
priv_nets = "{,,, }"

set skip on lo0

scrub in all

nat on $ext_if from { } to any -> ($ext_if)
rdr on $ext_if proto tcp from any to ($ext_if) port 5060 -> $core port 5060
rdr on $ext_if proto tcp from any to ($ext_if) port 5061 -> $core port 5061
rdr on $ext_if proto udp from any to ($ext_if) port 5060 -> $core port 5060
rdr on $ext_if proto udp from any to ($ext_if) port 5061 -> $core port 5061

block all

antispoof quick for $ext_if inet

pass in on $ext_if inet proto tcp from any to ($ext_if) port 15352 flags
S/SA keep state
pass in on $ext_if inet proto tcp from any to ($ext_if) port www flags S/SA
synproxy state
pass in on $ext_if proto udp from any to any port 5060 keep state
pass in on $ext_if proto udp from any to any port 5061 keep state
pass in on $ext_if proto tcp from any to any port 5060 keep state
pass in on $ext_if proto tcp from any to any port 5061 keep state

pass out on $ext_if proto tcp all modulate state flags S/SA
pass out on $ext_if proto {udp, icmp} all keep state

pass in on $int_if from $int_if:network to any
pass out on $int_if from any to $int_if:network

Reply via email to