passing to inside interface

2007-03-20 Thread Lawrence Horvath
this is on OpenBSD 4.0 Generic I have the below rule set in my pf.conf, i am having the following problem, i need to be able to log into the firewall with ssh from outside, and nothing should be able to hit the firewall from inside, not even ping from outside i can hit the shadow server, ssh, pi

Re: passing to inside interface

2007-03-20 Thread Stuart Henderson
On 2007/03/20 04:41, Lawrence Horvath wrote: > I have the below rule set in my pf.conf, i am having the following > problem, i need to be able to log into the firewall with ssh from > outside, and nothing should be able to hit the firewall from inside, > not even ping You don't "pass out" anything

Re: passing to inside interface

2007-03-20 Thread Lawrence Horvath
On 20/03/07, Stuart Henderson <[EMAIL PROTECTED]> wrote: On 2007/03/20 04:41, Lawrence Horvath wrote: > I have the below rule set in my pf.conf, i am having the following > problem, i need to be able to log into the firewall with ssh from > outside, and nothing should be able to hit the firewall

Re: passing to inside interface

2007-03-20 Thread Stuart Henderson
On 2007/03/20 06:18, Lawrence Horvath wrote: > On 20/03/07, Stuart Henderson <[EMAIL PROTECTED]> wrote: > >On 2007/03/20 04:41, Lawrence Horvath wrote: > >> I have the below rule set in my pf.conf, i am having the following > >> problem, i need to be able to log into the firewall with ssh from > >>

Re: passing to inside interface

2007-03-20 Thread Lawrence Horvath
is there a way to tag the packets going to pflog, i can see the packets being blocked with tcpdump on /var/log/pflog, but i would like to know what rule is blocking them i changed my rules a little bit here is the output of pfctl -s rules, i was hoping that explictly defining some of these would

Re: passing to inside interface

2007-03-20 Thread Stuart Henderson
On 2007/03/20 09:24, Lawrence Horvath wrote: > is there a way to tag the packets going to pflog, i can see the > packets being blocked with tcpdump on /var/log/pflog, but i would like > to know what rule is blocking them if you use '-e' to tcpdump, it dumps the link-layer headers - on a pflog(4) i

Re: passing to inside interface

2007-03-20 Thread Lawrence Horvath
On 20/03/07, Stuart Henderson <[EMAIL PROTECTED]> wrote: On 2007/03/20 09:24, Lawrence Horvath wrote: > is there a way to tag the packets going to pflog, i can see the > packets being blocked with tcpdump on /var/log/pflog, but i would like > to know what rule is blocking them if you use '-e' to

Re: passing to inside interface

2007-03-20 Thread Darren Spruell
On 3/20/07, Lawrence Horvath <[EMAIL PROTECTED]> wrote: On 20/03/07, Stuart Henderson <[EMAIL PROTECTED]> wrote: > On 2007/03/20 09:24, Lawrence Horvath wrote: > > is there a way to tag the packets going to pflog, i can see the > > packets being blocked with tcpdump on /var/log/pflog, but i would