Re: help on rewriting ftp-proxy rules for 4.7 up

2010-08-18 Thread Henning Brauer
* Peter N. M. Hansteen [2010-08-17 12:09]: > Dimitar Vassilev writes: > > > $tg_in on $ext_if inet proto udp from any to any port=syslog > > $tg_in on $ext_if from any to any flags P/FSRPAUEW > > $tg_in on $ext_if from any to any flags FPU/FSRPAUEW > > $tg_in on $ext_if from any to any flags FPU

Re: help on rewriting ftp-proxy rules for 4.7 up

2010-08-17 Thread Dimitar Vassilev
2010/8/17 Peter N. M. Hansteen : > Dimitar Vassilev writes: > >> $tg_in on $ext_if inet proto udp from any to any port=syslog >> $tg_in on $ext_if from any to any flags P/FSRPAUEW >> $tg_in on $ext_if from any to any flags FPU/FSRPAUEW >> $tg_in on $ext_if from any to any flags FPU/FPU >> $tg_in o

Re: help on rewriting ftp-proxy rules for 4.7 up

2010-08-17 Thread Peter N. M. Hansteen
Dimitar Vassilev writes: > $tg_in on $ext_if inet proto udp from any to any port=syslog > $tg_in on $ext_if from any to any flags P/FSRPAUEW > $tg_in on $ext_if from any to any flags FPU/FSRPAUEW > $tg_in on $ext_if from any to any flags FPU/FPU > $tg_in on $ext_if from any to any flags /FSRA > $

Re: help on rewriting ftp-proxy rules for 4.7 up

2010-08-16 Thread Theo de Raadt
> $tg_in on $ext_if inet proto udp from any to any port=syslog if people keep doing this bullshit I will remove macros from pf.

Re: help on rewriting ftp-proxy rules for 4.7 up

2010-08-16 Thread Dimitar Vassilev
Thanks James, Tried this with my original ruleset from http://logbook.oldbonez.net/index.php?p=39&more=1&c=1&tb=1&pb=1 I ran the script and was left with one thing rdr pass on $int_if proto tcp from $int_net to any port ftp -> 127.0.0.1 port 8021 If I rewrite it to: block log on $ext_if all $t

help on rewriting ftp-proxy rules for 4.7 up

2010-08-16 Thread Dimitar Vassilev
Hello all, running OpenBSD 4.8 snapshot of Aug 16th on Alix 1D box. Rewrote my old pf rules to the new grammar for nat and ftp . Connection to ftp servers work, however ls and dir commands fail with connect failed: Network is unreachable. connect failed: Network is unreachable. connect failed: Netw