Re: PF in FreeBSD 10.0 Blocking Some SSH

2014-02-12 Thread Gleb Smirnoff
On Mon, Jan 27, 2014 at 10:22:30PM -0500, Robert Simmons wrote: R> > On Sun, Jan 26, 2014 at 06:19:34PM -0500, Robert Simmons wrote: R> > R> Over the course of a few hours there are a handful of SSH packets that R> > R> are being blocked both in and out. This does not seem to affect the R> > R> SSH

Re: PF in FreeBSD 10.0 Blocking Some SSH

2014-01-27 Thread Jason Hellenthal
Interesting I'll see if I can plug away with this and produce something similar to that using your rules once I can get past this kernel problem I have . . . ;-) definately a point release -- Jason Hellenthal Voice: 95.30.17.6/616 JJH48-ARIN > On Jan 27, 2014, at 22:26, Robert Simmons wro

Re: PF in FreeBSD 10.0 Blocking Some SSH

2014-01-27 Thread Robert Simmons
On Mon, Jan 27, 2014 at 4:06 PM, Jason Hellenthal wrote: > > I've seen similar things happen on SSH, that were due to a combination of > "scrub"ing and states expiring. Turning off scrub rules on SSH specifically > cured the scenario for me but I don't see an indication of whether or not > you are

Re: PF in FreeBSD 10.0 Blocking Some SSH

2014-01-27 Thread Robert Simmons
On Mon, Jan 27, 2014 at 2:20 PM, Gleb Smirnoff wrote: > Robert, > > On Sun, Jan 26, 2014 at 06:19:34PM -0500, Robert Simmons wrote: > R> Over the course of a few hours there are a handful of SSH packets that > R> are being blocked both in and out. This does not seem to affect the > R> SSH sessio

Re: PF in FreeBSD 10.0 Blocking Some SSH

2014-01-27 Thread Jason Hellenthal
I've seen similar things happen on SSH, that were due to a combination of "scrub"ing and states expiring. Turning off scrub rules on SSH specifically cured the scenario for me but I don't see an indication of whether or not you are using that. You could also verify the states dropping by chang

Re: PF in FreeBSD 10.0 Blocking Some SSH

2014-01-27 Thread Gleb Smirnoff
Robert, On Sun, Jan 26, 2014 at 06:19:34PM -0500, Robert Simmons wrote: R> Over the course of a few hours there are a handful of SSH packets that R> are being blocked both in and out. This does not seem to affect the R> SSH session, and all the blocked packets have certain flags set [FP.], R> [R

PF in FreeBSD 10.0 Blocking Some SSH

2014-01-26 Thread Robert Simmons
Over the course of a few hours there are a handful of SSH packets that are being blocked both in and out. This does not seem to affect the SSH session, and all the blocked packets have certain flags set [FP.], [R.], [P.], [.], [F.]. The following is my ruleset abbreviated to the rules that apply to