Dear Stuart. The translation is offcourse BEFORE the filtering ! Any other thoughts about the problem ?
On 6/13/06, Stuart Henderson <[EMAIL PROTECTED]> wrote: > > On 2006/06/13 05:26, Alex Stamatis wrote: > > I have a veeeryyy veeeryyy weird problem !!! > > Not really... > > > I have small network. The Openbsd box (3.7 generic) is my firewall. > > In 2 of my windows workstations I wont to have remote desktop. So I make > a > > pass in rule for the ports 65500 and 65501 and a rdr of these 2 ports > 65500 > > to 1 ip at 3389 internal port and the 65501 to another ip in 3389. > > It wont play from the outside world. > > Read the first couple of paragraphs of the TRANSLATION section of > pf.conf(5), then you'll see that translation comes *before* filtering.