Re: reply-to for blocked packets

2015-08-04 Thread Giancarlo Razzolini
Em 04-08-2015 04:52, Kapetanakis Giannis escreveu: > I've already have rules for outgoing traffic that utilize route-to. > However this applies only for new packets generated from host itself. > It does not match on returns. Not necessarily true. You can filter on your outgoing interfaces as this:

Re: reply-to for blocked packets

2015-08-04 Thread Kapetanakis Giannis
On 03/08/15 16:45, Giancarlo Razzolini wrote: Em 03-08-2015 05:23, Kapetanakis Giannis escreveu: Is there a way to sort this out and route packets to the correct interface? You can try to create "enforcing" rules. Create 2 rules in your outgoing interfaces that, when they detect a packet leavin

Re: reply-to for blocked packets

2015-08-03 Thread Giancarlo Razzolini
Em 03-08-2015 05:23, Kapetanakis Giannis escreveu: > Is there a way to sort this out and route packets to the correct > interface? You can try to create "enforcing" rules. Create 2 rules in your outgoing interfaces that, when they detect a packet leaving a interface but it should be on the other,

reply-to for blocked packets

2015-08-03 Thread Kapetanakis Giannis
Hi, I have a server with 2 vlan interfaces + 2 carped interfaces. Replies for blocked connections (tcp reset or icmp port unreachable) are coming out through the wrong interface (ie always on default gw). Near the end of my pf.conf I have the following rules: @49: block return in quick log on