Re: Who is 'anchor 11' (pfctl -vvss ./. pfctl -vsA)?

2019-01-03 Thread Philipp Buehler
Am 02.01.2019 21:35 schrieb Klemens Nanni: Anchor 11 is the twelfth rule in your main ruleset (the anchor rule), in which the first rule established this state. Ouch, overlooked this one. Thanks.. Provide your ruleset so we can look at actual rules without guessing in case your problem persis

Re: Who is 'anchor 11' (pfctl -vvss ./. pfctl -vsA)?

2019-01-02 Thread Klemens Nanni
On Wed, Jan 02, 2019 at 07:09:54PM +0100, Philipp Buehler wrote: > 'pfctl -vvss': > all tcp 10.45.30.7:993 (public-nat:993) <- remote-ip:4690 > ESTABLISHED:ESTABLISHED >[1683650613 + 66296] wscale 7 [3702552199 + 16768] wscale 2 >age 04:32:22, expires in 00:09:25, 745:737 pkts, 55579:87226

Who is 'anchor 11' (pfctl -vvss ./. pfctl -vsA)?

2019-01-02 Thread Philipp Buehler
Hello, in the midst of debugging ruleset/migrations, I came across this output in 'pfctl -vvss': all tcp 10.45.30.7:993 (public-nat:993) <- remote-ip:4690 ESTABLISHED:ESTABLISHED [1683650613 + 66296] wscale 7 [3702552199 + 16768] wscale 2 age 04:32:22, expires in 00:09:25, 745:737