Re: pf and DNS

2011-01-07 Thread Andy Bradford
Thus said Girish Venkatachalam on Fri, 07 Jan 2011 16:26:01 +0530: > Due to this , whatever IP address pf(4) knows at the time of ruleset > loading alone works. Use pfctl and a cronjob to periodically update a table. Kludgey, sure... Andy

Re: pf and DNS

2011-01-07 Thread Christopher Dukes
On Fri, 2011-01-07 at 16:26 +0530, Girish Venkatachalam wrote: > On Fri, Jan 7, 2011 at 2:43 PM, Martin Schrvder wrote: > >> > >> And consequently pf which does not know a thing about domains does not help > us. > > > > What exactly is the problem you want to solve? > > > > Sorry for having been

Re: pf and DNS

2011-01-07 Thread Joachim Schipper
On Fri, Jan 07, 2011 at 05:50:25AM -0500, Eric Furman wrote: > > On Fri, Jan 07 2011 at 59:07, Girish Venkatachalam wrote: > > > Many websites these days "Akamize" or do whatever that gives them a > > > different IP address > > > everytime you access it. > Don't use stupid shit like "Akamize". Pro

Re: pf and DNS

2011-01-07 Thread Girish Venkatachalam
On Fri, Jan 7, 2011 at 2:43 PM, Martin Schrvder wrote: >> >> And consequently pf which does not know a thing about domains does not help us. > > What exactly is the problem you want to solve? > Sorry for having been abstract. Here is the detailed explanation. One domain translates to around 100

Re: pf and DNS

2011-01-07 Thread Eric Furman
Don't use stupid shit like "Akamize". Problem solved. Stop making people laugh at you. On Fri, 07 Jan 2011 10:25 +0100, "Claer" wrote: > On Fri, Jan 07 2011 at 59:07, Girish Venkatachalam wrote: > > I try to use OpenBSD wherever I can and in the firewall I have > > installed in a big jewel store

Re: pf and DNS

2011-01-07 Thread Claer
On Fri, Jan 07 2011 at 59:07, Girish Venkatachalam wrote: > I try to use OpenBSD wherever I can and in the firewall I have > installed in a big jewel store > here I have the following problem. > > Many websites these days "Akamize" or do whatever that gives them a > different IP address > everytim

Re: pf and DNS

2011-01-07 Thread Martin Schröder
2011/1/7 Girish Venkatachalam : > Many websites these days "Akamize" or do whatever that gives them a > different IP address > everytime you access it. > > And consequently pf which does not know a thing about domains does not help > us. What exactly is the problem you want to solve? Best Mar

pf and DNS

2011-01-06 Thread Girish Venkatachalam
I try to use OpenBSD wherever I can and in the firewall I have installed in a big jewel store here I have the following problem. Many websites these days "Akamize" or do whatever that gives them a different IP address everytime you access it. And consequently pf which does not know a thing about

Re: PF and DNS requests

2005-11-11 Thread Matthew R Powell
Chris Kuethe wrote: On 11/11/05, Matthew R Powell <[EMAIL PROTECTED]> wrote: Greetings, My 3.7 firewall is holding up DNS requests. pflog suggests that my very first rule, 'block log all' is stopping them. As it should. Further down my rule set, however, exists the following ru

Re: PF and DNS requests

2005-11-11 Thread Chris Kuethe
On 11/11/05, Matthew R Powell <[EMAIL PROTECTED]> wrote: > Greetings, > > My 3.7 firewall is holding up DNS requests. pflog suggests that my very > first rule, 'block log all' is stopping them. As it should. > Further down my rule set, however, exists the following rule: > pass out quick log on

Re: PF and DNS requests

2005-11-11 Thread Lars Hansson
On Fri, 11 Nov 2005 02:40:08 -0600 Matthew R Powell <[EMAIL PROTECTED]> wrote: > Nov 11 02:11:48.853946 rule 0/(match) block in on xl0: > 192.168.2.254.60399 > 68.12.16.229.53: 23554+[|domain] (DF) > > Further down my rule set, however, exists the following rule: > pass out quick log on $ext_if

PF and DNS requests

2005-11-11 Thread Matthew R Powell
Greetings, My 3.7 firewall is holding up DNS requests. pflog suggests that my very first rule, 'block log all' is stopping them. Nov 11 02:11:48.853946 rule 0/(match) block in on xl0: 192.168.2.254.60399 > 68.12.16.229.53: 23554+[|domain] (DF) Further down my rule set, however, exists the