Re: pf from self user _rebound to port 53 and rebound in front of unbound

2016-04-12 Thread Craig Skinner
Hi Kevin/Jeremie/all, On 2016-04-11 Mon 13:57 PM |, Jeremie Courreges-Anglas wrote: > Kevin Chadwick writes: > > >> Something like > >> > >> pass out ... proto udp from any to any port 53 user = _rebound > >> > >> same for tcp. > > > > Yeah but have you tried it and been successful without g

Re: pf from self user _rebound to port 53 and rebound in front of unbound

2016-04-11 Thread Jeremie Courreges-Anglas
Kevin Chadwick writes: >> Something like >> >> pass out ... proto udp from any to any port 53 user = _rebound >> >> same for tcp. > > Yeah but have you tried it and been successful without getting a syntax > error? This doesn't give a syntax error and seems to do what you're looking for. s/

Re: pf from self user _rebound to port 53 and rebound in front of unbound

2016-04-11 Thread Kevin Chadwick
> Something like > > pass out ... proto udp from any to any port 53 user = _rebound > > same for tcp. Yeah but have you tried it and been successful without getting a syntax error? -- KISSIS - Keep It Simple So It's Securable

Re: pf from self user _rebound to port 53 and rebound in front of unbound

2016-04-08 Thread Jeremie Courreges-Anglas
Kevin Chadwick writes: > I know rebound is not meant for this and see it's benefits for clients > and even maybe in front of unbound. > > However after noticing rebound and the undeadly thread I played with PF > to see if I could enforce all DNS requests to have come from rebound. > > The best I

pf from self user _rebound to port 53 and rebound in front of unbound

2016-04-08 Thread Kevin Chadwick
I know rebound is not meant for this and see it's benefits for clients and even maybe in front of unbound. However after noticing rebound and the undeadly thread I played with PF to see if I could enforce all DNS requests to have come from rebound. The best I have managed so far without syntax er