login
Header Space

 
 

Re: PF Config problem

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <misc@...>
Date: Friday, July 20, 2007 - 5:46 am

>>> On 20 July 2007 at 10:04, in message
<20070720090413.GK3317@bootes.spacehopper.org>, Stuart Henderson
<stu@spacehopper.org> wrote:
destination,

Phew ! I thought my brain had gone the same way as my hair... ;-)


I did:

pass in on $int_if proto tcp from 172.16.2.34 to 192.168.249.3 keep state
pass out on $out_if

and that worked.


I then did:

pass in on $int_if proto tcp from 172.16.2.34 to 192.168.249.3 tag TEST_TAG
keep state
pass out on $out_if tagged TEST_TAG

and that worked as well - and (I believe) is tighter than just a "pass out".
(Certainly solves my paranoid problem in my previous posting)

Going off on a tangent here: Why is it that I've just picked this up and
no-one else has ? Is it because I'm running in full paranoia mode and blocking
*everything* unless explicitly allowed ?

I haven't tried your diff - let me know if you want me to.

Thanks for your help, much appreciated.

GTG
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
PF Config problem, Gordon Ross, (Thu Jul 19, 10:38 am)
Re: PF Config problem, Stuart Henderson, (Thu Jul 19, 6:52 pm)
Re: PF Config problem, Gordon Ross, (Fri Jul 20, 4:49 am)
Re: PF Config problem, Gordon Ross, (Fri Jul 20, 3:45 am)
Re: PF Config problem, Stuart Henderson, (Fri Jul 20, 5:04 am)
Re: PF Config problem, Gordon Ross, (Fri Jul 20, 5:46 am)
Re: PF Config problem, Stuart Henderson, (Fri Jul 20, 6:33 am)
Re: PF Config problem, Dag Richards, (Thu Jul 19, 11:55 am)
speck-geostationary