set misc digest-daily

2009-11-19 Thread S. Scott
set misc digest-daily

openbsd 4.2 + ftp-proxy -T + pf +tag/tagged not working

2007-12-10 Thread S. Scott Sima, CISA, CISM
Using openbsd 4.2, pf and ftp-proxy. ftp-proxy -T is not being recognized by pf.conf ruleset. In the NOT WORKING (snip) below, the tcpdump shows the ftp-proxied packets being ignored by the tagged pass rule and hitting on the final block all rule. ftp-proxy invoked as /usr/sbin/ftp-proxy -TOKF

Re: openbsd 4.2 + ftp-proxy -T + pf +tag/tagged not working

2007-12-11 Thread S. Scott Sima, CISA, CISM
rs are ZERO for the "tagged " version and otherwise correct and incrementing for "user proxy" version. -Original Message- From: Camiel Dobbelaar <[EMAIL PROTECTED]> To: S. Scott Sima, CISA, CISM <[EMAIL PROTECTED]> Cc: misc@openbsd.org Subject: Re: openbsd 4

pf anchors with tag/tagged

2008-02-08 Thread S. Scott Sima, CISA, CISM
(sorry, orig post errantly had no subject) Trying to redact (simplify) pf rdr statements by moving the repeating (common) criteria to the top. The rules load error free. The pfctl -vvsnat shows the rdr-anchor in place; however, tcpdump shows the block rules being hit AS IF THE TAG/TAGGED IS NOT

pf+queue+pass in+statfeful out

2008-02-27 Thread S. Scott Sima, CISA, CISM
I know queuing only applies to outbound traffic. I'm using "ssh -w" tunnelling to the pf+gateway. I, therefore, have pass in on #ext_if inet proto tcp ... keep state queue (QSHH, QLOWLAT), which, if I understand correctly, should assign the stateful reply/return (outbound) traffic be queued on