Re: New pf install on Freebsd seem to be a slow starter.

2008-07-09 Thread Leslie Jensen
Stuart Henderson skrev: On 2008/07/09 19:25, Leslie Jensen wrote: table { something.somewhere.com, somethingelse.somewhere.com, xxx.yyy.zzz.qqq } With DNS names? That's likely to be your problem. Oh, I didn't know that! Can you tell me how to handle this? The problem is these

Re: New pf install on Freebsd seem to be a slow starter.

2008-07-10 Thread Leslie Jensen
Peter N. M. Hansteen skrev: Leslie Jensen <[EMAIL PROTECTED]> writes: With DNS names? That's likely to be your problem. Oh, I didn't know that! Can you tell me how to handle this? The problem is that this makes your ruleset load dependent on working name resolution,

Re: New pf install on Freebsd seem to be a slow starter.

2008-07-10 Thread Leslie Jensen
Peter N. M. Hansteen skrev: Leslie Jensen <[EMAIL PROTECTED]> writes: With DNS names? That's likely to be your problem. Oh, I didn't know that! Can you tell me how to handle this? The problem is that this makes your ruleset load dependent on working name resolution,

forwarding loop

2013-01-12 Thread Leslie Jensen
For the last five years I've had a machine with two NIC's running as an Internet gateway, firewall and proxy server. OS is FreeBSD 8.2-RELEASE. With the introduction of Squid 3.2 I ran inte a problem that I need help solving. Squid has now begone to complain about a forwarding loop and I've

Re: forwarding loop

2013-01-14 Thread Leslie Jensen
2013-01-14 10:50, Daniel Hartmeier skrev: On Sat, Jan 12, 2013 at 08:03:41AM +0100, Leslie Jensen wrote: New suggested rule that gives syntax error # rdr in on $int_if inet proto tcp from ! $proxy to any port $proxy_services -> $proxy $proxyport tag rdr_proxy 1) Remove "in"

Re: forwarding loop

2013-01-15 Thread Leslie Jensen
2013-01-15 11:10, Daniel Hartmeier skrev: Wait, the squid server is on a separate host, on the $int_if side of the firewall (the same side the clients are on)? Then transparent proxying would require "reflection", and doesn't work, see http://www.openbsd.org/faq/pf/rdr.html#reflect If squid i

Re: forwarding loop

2013-01-15 Thread Leslie Jensen
2013-01-15 12:01, Daniel Hartmeier skrev: On Tue, Jan 15, 2013 at 11:50:14AM +0100, Leslie Jensen wrote: 2013-01-15 11:10, Daniel Hartmeier skrev: Wait, the squid server is on a separate host, on the $int_if side of the firewall (the same side the clients are on)? Yes! This machine has

Re: forwarding loop

2013-01-16 Thread Leslie Jensen
2013-01-15 12:49, Daniel Hartmeier skrev: You currently have the following rules pass out log on $ext_if inet proto tcp from $proxy to any port $proxy_services keep state # pass out pass out log What's the point of these? Whenever the first rule would match, the second one would al

Re: forwarding loop

2013-01-16 Thread Leslie Jensen
2013-01-16 10:56, Daniel Hartmeier skrev: On Wed, Jan 16, 2013 at 10:19:45AM +0100, Leslie Jensen wrote: The squid access.log says tcp_miss which should mean that the website has not replied. The browser shows the squid access denied screen. I cannot see any denied packets with tcpdump

Re: forwarding loop

2013-01-16 Thread Leslie Jensen
2013-01-16 10:56, Daniel Hartmeier skrev: On Wed, Jan 16, 2013 at 10:19:45AM +0100, Leslie Jensen wrote: The squid access.log says tcp_miss which should mean that the website has not replied. The browser shows the squid access denied screen. I cannot see any denied packets with tcpdump