Re: NAT, Firewall & pf

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: patrick keshishian
Date: Wednesday, February 25, 2009 - 6:39 pm

On Wed, Feb 25, 2009 at 5:15 PM, Jason Dixon <jason@dixongroup.net> wrote:

The floating states based on line 10 would be for pre-NAT sources on
$int_if and wouldn't match any inbound packets on $ext_if. Unless I'm
misunderstanding how NAT works with pf, there are no pass out rules
that would create states for these packets:

from pf.conf(5):

     Since translation occurs before filtering the filter engine will see
     packets as they look after any addresses and ports have been translated.
     Filter rules will therefore have to filter based on the translated ad-
     dress and port number.  Packets that match a translation rule are only
     automatically passed if the pass modifier is given, otherwise they are
     still subject to block and pass rules.
     ...
     Translation rules apply only to packets that pass through the specified
     interface, and if no interface is specified, translation is applied to
     packets on all interfaces.

--patrick
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
NAT, Firewall &amp; pf, Hilco Wijbenga, (Mon Feb 23, 6:58 pm)
Re: NAT, Firewall &amp; pf, kevin thompson, (Mon Feb 23, 9:09 pm)
Re: NAT, Firewall &amp; pf, patrick keshishian, (Mon Feb 23, 9:32 pm)
Re: NAT, Firewall &amp; pf, Jason Dixon, (Mon Feb 23, 9:33 pm)
Re: NAT, Firewall &amp; pf, patrick keshishian, (Mon Feb 23, 9:37 pm)
Re: NAT, Firewall &amp; pf, johan beisser, (Mon Feb 23, 9:47 pm)
Re: NAT, Firewall &amp; pf, Jason Dixon, (Mon Feb 23, 9:55 pm)
Re: NAT, Firewall &amp; pf, patrick keshishian, (Mon Feb 23, 10:11 pm)
Re: NAT, Firewall &amp; pf, patrick keshishian, (Mon Feb 23, 10:13 pm)
Re: NAT, Firewall &amp; pf, johan beisser, (Mon Feb 23, 10:18 pm)
Re: NAT, Firewall &amp; pf, Toni Mueller, (Tue Feb 24, 3:09 am)
Re: NAT, Firewall &amp; pf, (private) HKS, (Tue Feb 24, 6:52 am)
Re: NAT, Firewall &amp; pf, Jorge Enrique Valbue ..., (Tue Feb 24, 7:38 am)
Re: NAT, Firewall &amp; pf, Hilco Wijbenga, (Tue Feb 24, 10:08 am)
Re: NAT, Firewall &amp; pf, Hilco Wijbenga, (Tue Feb 24, 10:10 am)
Re: NAT, Firewall &amp; pf, (private) HKS, (Tue Feb 24, 10:48 am)
Unfortunate dot was ... missing, Jean-Francois, (Tue Feb 24, 11:43 am)
Re: Unfortunate dot was ... missing, Jason Dixon, (Tue Feb 24, 11:55 am)
Re: Unfortunate dot was ... missing, Etienne Robillard, (Tue Feb 24, 12:05 pm)
Re: Unfortunate dot was ... missing, Tim Donahue, (Tue Feb 24, 12:10 pm)
Re: Unfortunate dot was ... missing, Daniel A. Ramaley, (Tue Feb 24, 12:10 pm)
Re: Unfortunate dot was ... missing, Tony Abernethy, (Tue Feb 24, 12:12 pm)
Re: Unfortunate dot was ... missing, richardtoohey, (Tue Feb 24, 12:12 pm)
Re: NAT, Firewall &amp; pf, Hilco Wijbenga, (Tue Feb 24, 10:48 pm)
Re: NAT, Firewall &amp; pf, Hilco Wijbenga, (Tue Feb 24, 10:49 pm)
Re: NAT, Firewall &amp; pf, patrick keshishian, (Tue Feb 24, 11:38 pm)
Re: NAT, Firewall &amp; pf, Jean-Francois, (Wed Feb 25, 12:20 am)
Re: NAT, Firewall &amp; pf, David Vasek, (Wed Feb 25, 3:45 am)
Re: NAT, Firewall &amp; pf, ropers, (Wed Feb 25, 5:07 pm)
Re: NAT, Firewall &amp; pf, patrick keshishian, (Wed Feb 25, 5:39 pm)
Re: NAT, Firewall &amp; pf, Rod Whitworth, (Wed Feb 25, 6:10 pm)
Re: NAT, Firewall &amp; pf, Jason Dixon, (Wed Feb 25, 6:15 pm)
Re: NAT, Firewall & pf, patrick keshishian, (Wed Feb 25, 6:39 pm)
Re: NAT, Firewall &amp; pf, Jason Dixon, (Wed Feb 25, 6:50 pm)
Re: NAT, Firewall &amp; pf, Jorge Enrique Valbue ..., (Wed Feb 25, 7:08 pm)
Re: NAT, Firewall &amp; pf, Rod Whitworth, (Wed Feb 25, 7:14 pm)
Re: NAT, Firewall &amp; pf, Jason Dixon, (Wed Feb 25, 7:27 pm)
Re: NAT, Firewall &amp; pf, Rod Whitworth, (Wed Feb 25, 9:05 pm)
Re: NAT, Firewall &amp; pf, Jason Dixon, (Wed Feb 25, 9:45 pm)
Re: NAT, Firewall &amp; pf, patrick keshishian, (Wed Feb 25, 9:53 pm)
Re: NAT, Firewall &amp; pf, patrick keshishian, (Wed Feb 25, 10:00 pm)
Re: NAT, Firewall &amp; pf, ropers, (Wed Feb 25, 10:47 pm)
Re: NAT, Firewall &amp; pf, Jason Dixon, (Wed Feb 25, 11:28 pm)