Re: synproxy issue

2008-12-05 Thread Darrin Chandler
Stephan, On Fri, Dec 05, 2008 at 09:14:10AM +0100, Stephan A. Rickauer wrote: > > $ lynx -dump -head http://cds.sun.com > > The matching pf rule is: > pass in log quick inet proto tcp to port http synproxy state > (with default pass out policy) > > However, the http connection stalls. Changing

Re: synproxy issue

2008-12-05 Thread Stephan A. Rickauer
On Fri, 2008-12-05 at 06:01 -0700, Darrin Chandler wrote: > Stephan, > > On Fri, Dec 05, 2008 at 09:14:10AM +0100, Stephan A. Rickauer wrote: > > > > $ lynx -dump -head http://cds.sun.com > > > > The matching pf rule is: > > pass in log quick inet proto tcp to port http synproxy state > > (with

synproxy issue

2008-12-05 Thread Stephan A. Rickauer
I seem to either not understand or having the following synproxy issue: A client (172.16.2.60) behind a firewall (nat, 4.4) does a http connect to cds.sun.com (72.5.239.134), requesting the header only: $ lynx -dump -head http://cds.sun.com The matching pf rule is: pass in log quick inet proto