Re: icmp-type echoreq not matching resulting ttl exceeded

2013-11-29 Thread Ermal Luçi
On Fri, Nov 29, 2013 at 2:53 PM, Ian FREISLICH wrote: > =?ISO-8859-1?Q?Ermal_Lu=E7i?= wrote: > > On Fri, Nov 29, 2013 at 1:28 PM, Ian FREISLICH wrote: > > > At some point this stopped working. I was able to use traceroute -I > > > This rule let the echo request out and the resulting TTL exceede

Re: icmp-type echoreq not matching resulting ttl exceeded

2013-11-29 Thread Ermal Luçi
On Fri, Nov 29, 2013 at 1:28 PM, Ian FREISLICH wrote: > Hi > > At some point this stopped working. I was able to use traceroute -I > This rule let the echo request out and the resulting TTL exceeded > was matched and allowed back in. > > Which freeBSD version you are testing this? Normally it s

icmp-type echoreq not matching resulting ttl exceeded

2013-11-29 Thread Ian FREISLICH
Hi At some point this stopped working. I was able to use traceroute -I This rule let the echo request out and the resulting TTL exceeded was matched and allowed back in. pass out inet proto icmp from to any icmp-type echoreq I've had to change the rule to the following to keep traceroute goi