Re: PF and states of connections with same src port

2008-05-04 Thread Jordi Espasa Clofent
It's related to timeout options. man pf.conf(5), Options sections, timeouts. By default, pf offers to you a three 'lists' of timeouts values: Conservative, Normal and Aggressive. If you want to drop completely the connections states early, you can use Aggressive staff. But PF is extremely fle

Re: PF and states of connections with same src port

2008-05-02 Thread B A
I found this notes http://www.openbsd.org/cgi-bin/cvsweb/src/sys/net/pf.c?rev=1.559&content-type=text/x-cvsweb-markup Will try upgrade (I'm running 4.1) and see 02.05.08, 20:21, "Kian Mohageri" <[EMAIL PROTECTED]>: > States aren't purged immediately. Take a look at the timeout val

Re: PF and states of connections with same src port

2008-05-02 Thread Kian Mohageri
On Fri, May 2, 2008 at 7:35 AM, B A <[EMAIL PROTECTED]> wrote: > Hello! > > > > I have question about PF. > > > > I have just found interesting behavior of of PF. > > For example if I fix source port and run from my PC: > >echo 'aaa' | nc -p www.my.rerver 80 > > I got response. > >

PF and states of connections with same src port

2008-05-02 Thread B A
Hello! I have question about PF. I have just found interesting behavior of of PF. For example if I fix source port and run from my PC: echo 'aaa' | nc -p www.my.rerver 80 I got response. But if I just run this command again - connection stuck. I should wait about 1 min to be