Re: [PF] Strange Blocks

2009-05-04 Thread Stuart Henderson
On 2009-05-03, dug wrote: > > Ok. It's just a mistake rewriting the rule in the mail. don't rewrite the rules, paste the pf.conf in exactly. if you are paranoid about IP addresses, *consistently* replace one byte of the address with some other value.

Re: [PF] Strange Blocks

2009-05-04 Thread dug
Le 4 mai 09 ` 14:59, ropers a icrit : Hang on, you're not running OpenBSD 4.5. What version are you running, and have you considered upgrading to the latest and greatest? regards, --ropers I'm running Openbsd 4.4. If I can't solve this issue, I will upgrade to 4.5. But I don't think, it's an

Re: [PF] Strange Blocks

2009-05-04 Thread ropers
2009/5/3 dug : > This is the result of pfctl -s rules : > > # pfctl -s rules > scrub all no-df random-id fragment reassemble Hang on, you're not running OpenBSD 4.5. What version are you running, and have you considered upgrading to the latest and greatest? regards, --ropers

Re: [PF] Strange Blocks

2009-05-03 Thread dug
Le 3 mai 09 ` 18:04, (private) HKS a icrit : Setting the rule "pass quick from any to any" at the beginning of my pf.conf file doesn't solve the problem. I always have block on these packets Logs of pftop tool : pfTop: Up Rule 1-55/71, View: rules, Cache: 1 RULE ACTION DIR LOG Q

Re: [PF] Strange Blocks

2009-05-03 Thread (private) HKS
On Sun, May 3, 2009 at 10:14 AM, dug wrote: > Thans for your reply. > > Le 2 mai 09 ` 10:59, ropers a icrit : > >> 2009/5/1 dug : >> 0> >> 1> #Allow SMTP, HTTPS >> 2> pass quick proto tcp from any to { } port >> 25 >> 3> pass quick proto tcp from any to { } port >> 443 >> 4> pass quick proto tcp f

Re: [PF] Strange Blocks

2009-05-03 Thread dug
Thans for your reply. Le 2 mai 09 ` 10:59, ropers a icrit : 2009/5/1 dug : 0> 1> #Allow SMTP, HTTPS 2> pass quick proto tcp from any to { } port 25 3> pass quick proto tcp from any to { } port 443 4> pass quick proto tcp from { } port 25 to any 5> pass quick proto tcp from { } port 25 to any 6>

Re: [PF] Strange Blocks

2009-05-02 Thread ropers
2009/5/1 dug : 0> 1> #Allow SMTP, HTTPS 2> pass quick proto tcp from any to { } port 25 3> pass quick proto tcp from any to { } port 443 4> pass quick proto tcp from { } port 25 to any 5> pass quick proto tcp from { } port 25 to any 6> pass quick proto tcp from any port 25 to { } 7> pass quick prot

Re: [PF] Strange Blocks

2009-05-01 Thread patrick keshishian
have you looked at the output from `pfctl -sr'? might give you a clue. --patrick On Fri, May 1, 2009 at 9:09 AM, dug wrote: > Hello, > > I have some filter problems with a new installed firewall with Openbsd 4.4 > using PF. > > This Firewall is connect to Internet and to a private network. > On

[PF] Strange Blocks

2009-05-01 Thread dug
Hello, I have some filter problems with a new installed firewall with Openbsd 4.4 using PF. This Firewall is connect to Internet and to a private network. On this private network there is another Freebsd router which is a connected to a second private network. On it, there is a mail serve