Re: iptables rule in pf

2008-05-09 Thread Daniel Roethlisberger
; >>> <[EMAIL PROTECTED]> wrote: > > > > >>>> Dear Community, > > > > >>>> > > > > >>>> I want to move some of our firewalls from Linux/iptables to > > > > >>>> FreeBSD/pf. > > >

Re: iptables rule in pf

2008-05-08 Thread Elliott Perrin
> > > >>>> > > > >>>> I want to move some of our firewalls from Linux/iptables to > > > >>>> FreeBSD/pf. > > > >>>> > > > >>>> After reading man pf.conf for a couple of minutes I coul

Re: iptables rule in pf

2008-05-08 Thread Ermal Luçi
On Thu, May 8, 2008 at 1:58 PM, Daniel Roethlisberger <[EMAIL PROTECTED]> wrote: > CZUCZY Gergely <[EMAIL PROTECTED]> 2008-05-08: >> On Thu, 08 May 2008 11:36:26 +0300 Oleksandr Samoylyk >> <[EMAIL PROTECTED]> wrote: >> > >> That iptables rule worked for any destination. >> > > You cannot rewrite a

Re: iptables rule in pf

2008-05-08 Thread Daniel Roethlisberger
CZUCZY Gergely <[EMAIL PROTECTED]> 2008-05-08: > On Thu, 08 May 2008 11:36:26 +0300 Oleksandr Samoylyk > <[EMAIL PROTECTED]> wrote: > > >> That iptables rule worked for any destination. > > > You cannot rewrite a packet's destination address to _any_ > > > destination. > > > > > > It's like you

Re: iptables rule in pf

2008-05-08 Thread Daniel Roethlisberger
to > > >>>> FreeBSD/pf. > > >>>> > > >>>> After reading man pf.conf for a couple of minutes I couldn't > > >>>> find the realization of such iptables rule in pf: > > >>>> > > >>>> ip

Re: iptables rule in pf

2008-05-08 Thread Elliott Perrin
t; >>> Oleksandr Samoylyk <[EMAIL PROTECTED]> wrote: > >>> > >>>> Dear Community, > >>>> > >>>> I want to move some of our firewalls from Linux/iptables to FreeBSD/pf. > >>>> > >>>> After reading ma

Re: iptables rule in pf

2008-05-08 Thread Elliott Perrin
On Thu, 2008-05-08 at 01:04 +0300, Oleksandr Samoylyk wrote: > Dear Community, > > I want to move some of our firewalls from Linux/iptables to FreeBSD/pf. > > After reading man pf.conf for a couple of minutes I couldn't find the > realization of such iptables rule in pf:

Re: iptables rule in pf

2008-05-08 Thread CZUCZY Gergely
On Thu, 08 May 2008 11:36:26 +0300 Oleksandr Samoylyk <[EMAIL PROTECTED]> wrote: > >> That iptables rule worked for any destination. > > You cannot rewrite a packet's destination address to _any_ destination. > > > > It's like you cannot submit a package at the post office with the > > destinat

Re: iptables rule in pf

2008-05-08 Thread Oleksandr Samoylyk
s to FreeBSD/pf. After reading man pf.conf for a couple of minutes I couldn't find the realization of such iptables rule in pf: iptables -t nat -A PREROUTING -i ethX -d ! my.smtp.server -p tcp --dport 25 -j DROP block in on $interface proto tcp from any to ! my.smtp.server port 25 i

Re: iptables rule in pf

2008-05-08 Thread Jeremy Chadwick
On Thu, May 08, 2008 at 10:16:12AM +0200, Jille wrote: > iptables -t nat -A PREROUTING -i ethX -p tcp --dport 2525 -j DNAT > --to-destination :25 > rdr on $interface proto tcp from any to port 2525 -> port 25 >>> I meant _any_ destination with 25 port. >>

Re: iptables rule in pf

2008-05-08 Thread Jille
s from Linux/iptables to FreeBSD/pf. After reading man pf.conf for a couple of minutes I couldn't find the realization of such iptables rule in pf: iptables -t nat -A PREROUTING -i ethX -d ! my.smtp.server -p tcp --dport 25 -j DROP block in on $interface proto tcp from any to ! my.sm

Re: iptables rule in pf

2008-05-08 Thread CZUCZY Gergely
to move some of our firewalls from Linux/iptables to FreeBSD/pf. > >> > >> After reading man pf.conf for a couple of minutes I couldn't find the > >> realization of such iptables rule in pf: > >> > >> iptables -t nat -A PREROUTING -i ethX -d ! my.smt

Re: iptables rule in pf

2008-05-08 Thread Oleksandr Samoylyk
ch iptables rule in pf: iptables -t nat -A PREROUTING -i ethX -d ! my.smtp.server -p tcp --dport 25 -j DROP block in on $interface proto tcp from any to ! my.smtp.server port 25 iptables -t nat -A PREROUTING -i ethX -p tcp --dport 2525 -j DNAT --to-destination :25 rdr on $interface proto tcp from

Re: iptables rule in pf

2008-05-07 Thread CZUCZY Gergely
On Thu, 08 May 2008 01:04:54 +0300 Oleksandr Samoylyk <[EMAIL PROTECTED]> wrote: > Dear Community, > > I want to move some of our firewalls from Linux/iptables to FreeBSD/pf. > > After reading man pf.conf for a couple of minutes I couldn't find the > realizatio

iptables rule in pf

2008-05-07 Thread Oleksandr Samoylyk
Dear Community, I want to move some of our firewalls from Linux/iptables to FreeBSD/pf. After reading man pf.conf for a couple of minutes I couldn't find the realization of such iptables rule in pf: iptables -t nat -A PREROUTING -i ethX -d ! my.smtp.server -p tcp --dport 25 -j DROP iptabl

iptables rule in pf

2008-05-07 Thread Oleksandr Samoylyk
Dear Community, I want to move some of our firewalls from Linux/iptables to FreeBSD/pf. After reading man pf.conf for a couple of minutes I couldn't find the realization of such iptables rule in pf: iptables -t nat -A PREROUTING -i ethX -d ! my.smtp.server -p tcp --dport 25 -j DROP ipt