login
Header Space

 
 

RE: FreeBSD PF 4.1 Inserts Flags S/SA Automatically to rules

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Tom Uffner <tom@...>, Kian Mohageri <kian.mohageri@...>
Cc: <freebsd-pf@...>
Date: Wednesday, May 14, 2008 - 8:08 pm

Hi Tom, 

I have just zeroed in the statistics and yes the state-mismatch is still
increasing. 

If I do enable logging, how would I know that packet is mismatched? 

Cheers, 

Mark
-----Original Message-----
From: Tom Uffner [mailto:tom@uffner.com] 
Sent: Thursday, 15 May 2008 11:55 a.m.
To: Kian Mohageri
Cc: Mark Pagulayan; freebsd-pf@freebsd.org
Subject: Re: FreeBSD PF 4.1 Inserts Flags S/SA Automatically to rules

Kian Mohageri wrote:
as
and

even if reloading the ruleset to include "keep state" and/or "flags
s/sa"
didn't sever pre-existing connections, it shouldn't cause that large a
number of mismatches.

when was the last time you zeroed the statistics? is the mismatch count
still increasing w/ the 7.0 stateful rules? you may need to add "log
(all)"
to find out where the state mismatches are coming from.
_______________________________________________
freebsd-pf@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-pf
To unsubscribe, send any mail to "freebsd-pf-unsubscribe@freebsd.org"
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
FreeBSD PF 4.1 Inserts Flags S/SA Automatically to rules, Mark Pagulayan, (Wed May 14, 6:45 pm)
RE: FreeBSD PF 4.1 Inserts Flags S/SA Automatically to rules, Mark Pagulayan, (Wed May 14, 8:08 pm)
RE: FreeBSD PF 4.1 Inserts Flags S/SA Automatically to rules, Mark Pagulayan, (Wed May 14, 10:52 pm)
RE: FreeBSD PF 4.1 Inserts Flags S/SA Automatically to rules, Mark Pagulayan, (Thu May 15, 10:13 pm)
speck-geostationary