Re: filter string

2005-06-01 Thread Kevin
On 6/1/05, Rogério Moura <[EMAIL PROTECTED]> wrote: > I like to know if PF can block packets by the content (type > patch-o-magic string of IPTABLES), because my network have connections > of skype and messenger, this programs use ports that are allowed in > the firewall, type 80, 443 and I not kno

Re: filter string

2005-06-01 Thread Jason Dixon
On Jun 1, 2005, at 1:48 PM, Rogério Moura wrote: Hello!! I like to know if PF can block packets by the content (type patch-o-magic string of IPTABLES), because my network have connections of skype and messenger, this programs use ports that are allowed in the firewall, type 80, 443 and I not kno

Re: Help with HFSC and PF

2005-06-01 Thread Tihomir Koychev
--- Edgar <[EMAIL PROTECTED]> wrote: > Hello, I was hoping someone could help me out with > HFSC and pf, I'm sending my > rules (pf.conf) in the body of this message (so > anyone can see them), the > problem here is that I have a queue rule called > emule, and a queue rule > default, both on

Re: redirecting traffic internally...

2005-06-01 Thread Bryan Irvine
Daniel wrote up a very nice howto a while back. Google for "transquid". --Bryan On 5/31/05, Henry <[EMAIL PROTECTED]> wrote: > I have a squid server setup within my internal network and it does > work since I can manually set the proxy information into my desktops > and I am good to go. But I wa

Re: redirecting traffic internally...

2005-06-01 Thread Eivind Hestnes
Make sure you have configured Squid to support ordinary HTTP/1.1 requests, as described in http://www.benzedrine.cx/transquid.html Henry wrote: I have a squid server setup within my internal network and it does work since I can manually set the proxy information into my desktops and I am go

filter string

2005-06-01 Thread Rogério Moura
Hello!! I like to know if PF can block packets by the content (type patch-o-magic string of IPTABLES), because my network have connections of skype and messenger, this programs use ports that are allowed in the firewall, type 80, 443 and I not know how block this programs can anybody help me?

Re: redirecting traffic internally...

2005-06-01 Thread stephen
hi. rdr on $int_if proto tcp from {$desktop1, $desktop2} to any port 80 -> $squidserver port 3128 should do the trick. stephen. On 6/1/05, Henry <[EMAIL PROTECTED]> wrote: > I have a squid server setup within my internal network and it does > work since I can manually set the proxy informatio

Help with HFSC and PF

2005-06-01 Thread Edgar
Hello, I was hoping someone could help me out with HFSC and pf, I'm sending my rules (pf.conf) in the body of this message (so anyone can see them), the problem here is that I have a queue rule called emule, and a queue rule default, both on $ext_if, and then I have a filter rule for all emule t

ALTQ on carp + pfsync?

2005-06-01 Thread Constant, Benjamin
Hello @list, I've 2 interface (internal em0 and external em1) on a FreeBSD 5.4 (stable) box acting as a router + traffic shaper. - Pfsync is using internal interface (don't have 3 nic in the box) to exchange data. - ATLQ is enabled on external interface (em1). - CARP is in use on both interface

redirecting traffic internally...

2005-06-01 Thread Henry
I have a squid server setup within my internal network and it does work since I can manually set the proxy information into my desktops and I am good to go. But I want to do transparent proxying.. Anyway since this isn't a squid mailing list... I am sure my problem is with my routing/firewa

RE: Firewall design?

2005-06-01 Thread tefol tefol
I am actually know designing the firewall my company would run through, I basically need to masquerade internal 192.168.x.x network to the outside world, and screen a lan of public ip addressed servers so they can access and be accessed from the outside. I do a similar thing, with two CARP