Re: What stupif mitake am I making?

2009-12-23 Thread Duncan Patton a Campbell
On Tue, 22 Dec 2009 11:35:31 -0500 stan st...@panix.com wrote: -- A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? A: Top-posting. Na. It's when they won't use a consistent quoting convention Dhu Q: What is the most

What stupif mitake am I making?

2009-12-22 Thread stan
I have a redundnat pair of firewalls (4.6) and I am trying to block access from outside to the subet set up fr pfsync. I have the following rules in pf.conf ext_if = bge0 int_if = eme0 match in all scrub (no-df) pass# to establish keep-state block in quick from 10.209.128.20 to

Re: What stupif mitake am I making?

2009-12-22 Thread Steve Shockley
On 12/22/2009 11:35 AM, stan wrote: int_if = eme0 ?

Re: What stupif mitake am I making?

2009-12-22 Thread stan
On Tue, Dec 22, 2009 at 12:51:11PM -0500, Steve Shockley wrote: On 12/22/2009 11:35 AM, stan wrote: int_if = eme0 ? Good catch. But the test is from the outsiide, so I don't think this mistake is what's causing my problems. What I want to do is block all tarffic relate to the pfsync

Re: What stupif mitake am I making?

2009-12-22 Thread stan
On Tue, Dec 22, 2009 at 12:51:11PM -0500, Steve Shockley wrote: On 12/22/2009 11:35 AM, stan wrote: int_if = eme0 ? OK. pfctl -s rules shows: r...@phfw2:etc# pfctl -s rule match in all scrub (no-df) block drop out quick inet from 192.168.254.0/24 to any block drop in quick inet from any