Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: strange results with pf

From: Daniel Hartmeier <daniel(at)benzedrine.cx>
Date: Wed Aug 20 2003 - 08:43:46 EDT

On Wed, Aug 20, 2003 at 04:30:16PM +0400, Alexei G. Malinin wrote:

> as I mentioned above I removed the rule "scrub in all"

You should now have 'log' on all block rules. If pf is blocking the probes, you should see the probes (not the icmp replies) logged in /var/log/pflog. If you don't, the block rules are not effective (or logging is not properly set up).

If you see the probes logged in /var/log/pflog, compare the matching rule number with pfctl -gvvsr output (the initial "@nr" part is the rule number). Does the rule blocking the probes really have 'return-icmp'?

If so, pf may be attempting to send a reply, but fails due to lacking routing table entries. You're not running a bridge, are you?

BTW, you can follow-up to pf@benzedrine.cx, I think we're cluttering tech@, not sure this is still on-topic here.

Daniel Received on Wed Aug 20 09:11:35 2003

Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:48:43 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library