Re: pf rdr-to (localhost ntpd) not always works

2022-09-15 Thread Kapetanakis Giannis
The problem/limitation is probably from local port binding of the client:123 which is used for both connections. I see other clients that use high ports for ntp queries that create multiple states without any problem. all udp 127.0.0.1:123 (remote_ntp1:123) <- y.y.y.y:54401   SINGLE:MULTIPL

Re: pf rdr-to (localhost ntpd) not always works

2022-09-15 Thread Kapetanakis Giannis
On 15/09/2022 15:06, Kapetanakis Giannis wrote: > The problem/limitation is probably from local port binding of the client:123 > which is used for both connections. > > I see other clients that use high ports for ntp queries that create multiple > states without any problem. > > all udp 127.0.0

pf rdr-to (localhost ntpd) not always works

2022-09-15 Thread Kapetanakis Giannis
Hi, I'm trying to enforce a local ntpd server (which is also our external firewall/router) for all connections and I have a very strange problem. Only one (dst) IP is allowed to create a state. After state expires a new dst IP can be used. fw# pfctl -sr -R 154 pass in log quick on $int_if inet