Re: Packet Filter nat-to issue

2014-02-28 Thread Loïc Blot
Thanks all, i will be careful in the future, and i don't forget to precise "inet" keyword :) -- Best regards, Loïc BLOT, Engineering UNIX Systems, Security and Network Engineer http://www.unix-experience.fr Le vendredi 28 février 2014 à 11:54 +0100, Mike Belopuhov a écrit : > On 28 February 20

Re: Packet Filter nat-to issue

2014-02-28 Thread Stuart Henderson
On 2014/02/28 11:54, Mike Belopuhov wrote: > On 28 February 2014 10:15, Loïc Blot wrote: > > Hello, > > i encounter a strange problem today on PF. I don't know if this i normal > > but the result is illogic. > > > > I have this rule: > > > > pass out quick proto tcp from to port { smtp smtps 587

Re: Packet Filter nat-to issue

2014-02-28 Thread Paul de Weerd
[stripping tech@ from Cc:] On Fri, Feb 28, 2014 at 11:54:12AM +0100, Mike Belopuhov wrote: | > pfctl -t __automatic_d309aaac_1 -T show | >2001:660:3bbb:::2 | >fe80::92b1:1cad:fe18:ea18 | > | > To resolve this problem i added inet keyword to my rule. | > | > Is this normal ? | | yes, y

Re: Packet Filter nat-to issue

2014-02-28 Thread Peter N. M. Hansteen
On Fri, Feb 28, 2014 at 10:15:15AM +0100, Lo?c Blot wrote: > i encounter a strange problem today on PF. I don't know if this i normal > but the result is illogic. > > I have this rule: > > pass out quick proto tcp from to port { smtp smtps 587 > imap imaps pop3 pop3s } nat-to $natto_iface the p

Re: Packet Filter nat-to issue

2014-02-28 Thread Henning Brauer
* Loïc Blot [2014-02-28 11:33]: > Is this normal ? yes. -- Henning Brauer, h...@bsws.de, henn...@openbsd.org BS Web Services GmbH, http://bsws.de, Full-Service ISP Secure Hosting, Mail and DNS Services. Dedicated Servers, Root to Fully Managed Henning Brauer Consulting, http://henningbrauer.co

Re: Packet Filter nat-to issue

2014-02-28 Thread Mike Belopuhov
On 28 February 2014 10:15, Loïc Blot wrote: > Hello, > i encounter a strange problem today on PF. I don't know if this i normal > but the result is illogic. > > I have this rule: > > pass out quick proto tcp from to port { smtp smtps 587 > imap imaps pop3 pop3s } nat-to $natto_iface > > Tables co

Packet Filter nat-to issue

2014-02-28 Thread Loïc Blot
Hello, i encounter a strange problem today on PF. I don't know if this i normal but the result is illogic. I have this rule: pass out quick proto tcp from to port { smtp smtps 587 imap imaps pop3 pop3s } nat-to $natto_iface Tables contain IPv4 addresses only. After applying this rule (i added