Unix Technical Forum

Re: strange results with pf

This is a discussion on Re: strange results with pf within the mailing.openbsd.tech forums, part of the OpenBSD category; --> On Wed, Aug 20, 2003 at 04:30:16PM +0400, Alexei G. Malinin wrote: > as I mentioned above I removed ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > mailing.openbsd.tech

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-18-2008, 06:33 AM
Daniel Hartmeier
 
Posts: n/a
Default Re: strange results with pf

On Wed, Aug 20, 2003 at 04:30:16PM +0400, Alexei G. Malinin wrote:

> as I mentioned above I removed the rule "scrub in all"
> I checked /var/log/pflog - there were no "protocol unreachable replies" :-(


You should now have 'log' on all block rules. If pf is blocking the
probes, you should see the probes (not the icmp replies) logged in
/var/log/pflog. If you don't, the block rules are not effective (or
logging is not properly set up).

If you see the probes logged in /var/log/pflog, compare the matching
rule number with pfctl -gvvsr output (the initial "@nr" part is the rule
number). Does the rule blocking the probes really have 'return-icmp'?

If so, pf may be attempting to send a reply, but fails due to lacking
routing table entries. You're not running a bridge, are you?

BTW, you can follow-up to pf@benzedrine.cx, I think we're cluttering
tech@, not sure this is still on-topic here.

Daniel

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 01:24 PM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com