Re: pf and FR tcp flags

2006-01-17 Thread Daniel Ouellet
pass in quick on $EXTIF inet proto tcp from any to 192.178.78.6 port www flags S/SA modulate state I think scrub are used on the ext inferface Check to see if you use scrub or not then that would answer your question below. So now to my question: is the above denied connections correct or s

Re: pf and FR tcp flags

2006-01-17 Thread Joachim Schipper
On Tue, Jan 17, 2006 at 08:21:52PM +, Johan Linner wrote: > Hi! > > We are running a pretty nice commercial firewall which obviously is > based on a stripped version of OpenBSD and pf ;) (yes I know... we are > planning on switching to our own OpenBSD installation as soon as > possibly, sti

pf and FR tcp flags

2006-01-17 Thread Johan Linner
Hi! We are running a pretty nice commercial firewall which obviously is based on a stripped version of OpenBSD and pf ;) (yes I know... we are planning on switching to our own OpenBSD installation as soon as possibly, still in the learning process though). Anyway we get alot of warnings abou