Bizarre pf/sendmail interaction

2013-12-17 Thread Tethys
My firewall died recently, so I replaced it with a new machine. Since I needed to reinstall the OS, I naturally went for 5.4, rather than whatever obsolete version I'd been using on the old machine. But now I can't get incoming email. My setup is something like: public mx ---> firewall ---

Re: Bizarre pf/sendmail interaction

2013-12-17 Thread Tethys
On Tue, Dec 17, 2013 at 5:30 PM, Aaron wrote: > Did you enable forwarding? > > net.inet.ip.forwarding Yes. Packets are being forwarded without problems, and it's working as a firewall exactly as you'd expect for outbound traffic. I can browse the web etc. But something strange is going on. Not o

Re: Bizarre pf/sendmail interaction

2013-12-17 Thread Aaron
Did you enable forwarding? net.inet.ip.forwarding Aaron On 12/17/13 11:25, Tethys wrote: My firewall died recently, so I replaced it with a new machine. Since I needed to reinstall the OS, I naturally went for 5.4, rather than whatever obsolete version I'd been using on the old machine. But no

Re: Bizarre pf/sendmail interaction

2013-12-17 Thread Craig R. Skinner
On 2013-12-17 Tue 17:05 PM |, Tethys wrote: > On Tue, Dec 17, 2013 at 4:43 PM, Craig R. Skinner > wrote: > > > I guess you have net.inet.forwarding=1 in /etc/sysctl.conf > > Yes, I do. I can browse the web etc from inside the firewall without problems. > > > Does the firewall also know where to

Re: Bizarre pf/sendmail interaction

2013-12-17 Thread Tethys
On Tue, Dec 17, 2013 at 7:51 PM, Jan Stary wrote: >> block in log >> block out log on $ext > > How could anyone help you knowing just these two lines? > Show your pf.conf I was trying to show that I only had two block lines and that they both should log when blocking packets. My rules are actual

Re: Bizarre pf/sendmail interaction

2013-12-17 Thread mia
On 12/17/13 21:11, Tethys wrote: On Tue, Dec 17, 2013 at 7:51 PM, Jan Stary wrote: block in log block out log on $ext How could anyone help you knowing just these two lines? Show your pf.conf I was trying to show that I only had two block lines and that they both should log when blocking pac

Re: Bizarre pf/sendmail interaction

2013-12-17 Thread Jan Stary
On Dec 18 02:11:55, tet...@gmail.com wrote: > On Tue, Dec 17, 2013 at 7:51 PM, Jan Stary wrote: > > >> block in log > >> block out log on $ext > > > > How could anyone help you knowing just these two lines? > > Show your pf.conf > > I was trying to show that I only had two block lines and that t

Re: Bizarre pf/sendmail interaction

2013-12-18 Thread Tethys
On Wed, Dec 18, 2013 at 7:54 AM, Jan Stary wrote: > So $riva is a member of $lokisafe, right? Bingo! I knew it would be something trivial that I'd overlooked. All working now. Thanks, Tet -- "Java is a DSL for taking large XML files and converting them to stack traces" -- Bulat Shakirzyanov

Re: Bizarre pf/sendmail interaction

2013-12-18 Thread Stuart Henderson
On 2013-12-18, Tethys wrote: > On Tue, Dec 17, 2013 at 7:51 PM, Jan Stary wrote: > >>> block in log >>> block out log on $ext >> >> How could anyone help you knowing just these two lines? >> Show your pf.conf > > I was trying to show that I only had two block lines and that they > both should log

Re: Bizarre pf/sendmail interaction

2013-12-18 Thread carlos albino garcia grijalba
i think that u will have to track down the packets tcpdump can be the solution, or disable blocking while u find the offensive rule then fix it! > Date: Tue, 17 Dec 2013 17:56:33 + > To: misc@openbsd.org > Subject: Re: Bizarre pf/sendmail interaction > From: skin...@britvault.