Re: PF Once rules are not removed from main anchor

2014-06-21 Thread Peter N. M. Hansteen
eneral, but quite possibly some of the relevant developers read this as well. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic"

How not to ask questions + some resources (was: Re: IP Filter Documentation.)

2013-05-05 Thread Peter N. M. Hansteen
both for this one and openbsd-misc, or for that matter openbsd-newbies). And finally, for PF examples there is one more oft-cited resource, my own The Book of PF (http://nostarch.com/pf2.htm) or the PF tutorial that it grew out of (http://home.nuug.no/~peter/pf/, which links to full text versions plu

Re: IP Filter Documentation.

2013-05-05 Thread Peter N. M. Hansteen
, the keyword 'self' expands to all addresses assigned to all interfaces on the host (as a man pf.conf and search for self would have told you). - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuu

Re: throttle traffic by amount of time or amount of used traffic in GB?

2013-04-12 Thread Peter N. M. Hansteen
scenario, have a slightly simpler script do the tables shuffling at a specific time (again assuming you slice your traffic according to table membership). Off the top of my head, I think those are the most workable options, I hope this was a tiny bit helpful. - Peter [1] http://home.nuug.

Re: Suggestion for a new feature, port code

2011-03-01 Thread Peter N. M. Hansteen
d to a proper treatment of port knocking in a blog post or article, and that may still happen given enough round tuits. In the meantime, the main points have already been presented. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://w

Re: trouble with new rdr syntax

2010-10-03 Thread Peter GILMAN
Stuart Henderson wrote: > On 2010/10/03 14:24, Peter GILMAN wrote: > > > > Marcus Larsson wrote: > > > > > On Tue, Sep 21, 2010 at 10:25:11PM -0400, Peter GILMAN wrote: > > > > > > > can anybody see what i'm missing? i'd love

Re: trouble with new rdr syntax

2010-10-03 Thread Peter GILMAN
Marcus Larsson wrote: > On Tue, Sep 21, 2010 at 10:25:11PM -0400, Peter GILMAN wrote: > > > can anybody see what i'm missing? i'd love to score some points > > for openbsd at my job (and i'll fall back to 4.6 if i have to) but > > i'd really lov

trouble with new rdr syntax

2010-09-21 Thread Peter GILMAN
ate can anybody see what i'm missing? i'd love to score some points for openbsd at my job (and i'll fall back to 4.6 if i have to) but i'd really love to get this working with 4.7. any insight would be much appreciated. thanks, peter gilman

Re: Restricting source with dDNS (dynamic DNS)

2009-12-20 Thread Peter N. M. Hansteen
tools in a very simple way. One could of course argue that a little sshd config would go a long way too, say enabling key based logins only (turning off password authentication) and disallowing root logins so on, but we don't know whether they've done that already. - Peter --

Re: Restricting source with dDNS (dynamic DNS)

2009-12-19 Thread Peter N. M. Hansteen
esets, with all the flexibility that comes with pf. but you're right, it requires ssh to be accessible in order to log in, and so may not be what the original poster was looking for. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bs

Re: Restricting source with dDNS (dynamic DNS)

2009-12-18 Thread Peter N. M. Hansteen
; that change with some frequency. > > Is there a straightforward way to incorporate dynamic ip source addresses in > the > pf ruleset? I'd say this sounds like a situation where authpf could come in quite handy. - P -- Peter N. M. Hansteen, member of the firs

Re: pf is blocking too much connections?

2009-11-14 Thread Peter N. M. Hansteen
x. One random thought - does your rule set include such things as limits on max number of connections? Pure speculation, of course, but it is one of many situations would fit the symptoms you describe. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bs

Re: syntax error while using scrub with OpenBSD 4.6

2009-10-28 Thread Peter N. M. Hansteen
scrub (reassemble tcp) or some variation (some other parameters are possible). It's in the official docs, but not all the other resources out there that your favorite search engine will turn up have caught up with the news yet. -- Peter N. M. Hansteen, member of the first RF

milter-checkrcpt

2009-05-25 Thread Peter Winkler
Hi, We are testing the milter milter-checkrcpt. Linux sendmail 8.13 to NovellGroupWise. Sometimes the Novellserver says "421 Service not available" (Server busy, some like that) ani it would be REJECT. So, would it not better, to say: If user avaible OK, if user not availble REJECT, all other

Re: max-src-port-states to limit 1:N source port states???

2009-04-16 Thread Peter N. M. Hansteen
hu st writes: > So could pf limit the maximum number of simultaneous state entries > that a single source IP's source port can create with a rule? > (borrow from man pf.conf :)) max-src-states? (see STATEFUL TRACKING OPTIONS in man 5 pf.conf) - P -- Peter N. M. Hansteen, membe

Re: dual ISP puzzle

2009-02-16 Thread Peter N. M. Hansteen
Michael Grigoni writes: > Please let us know what IRC server and channel you found for 'pf' > discussions; it would be very useful. FreeNode has a #pf channel. relatively low volume, at times quite useful. -- Peter N. M. Hansteen, member of the first RFC 1149 implemen

Re: pf overload keyword for TCP only?

2009-01-26 Thread Peter N. M. Hansteen
study the actual traffic and the inevitable tweaking of the parameters such as lowering number of allowed connections. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil

PF tutorial in London, Nov 26, 2008

2008-10-21 Thread Peter N. M. Hansteen
ng an intensive Full-day PF tutorial[2] featuring Book of PF[] 3author Peter Hansteen[4]. Click the links, then go to the OpenBSD events page[5] for ways to extend that away from work period. [1] http://www.ukuug.org/ [2] http://www.ukuug.org/events/pftutorial/ [3] http://nostarch.com/pf.htm [4]

Re: Routing VPNs through a second interface.

2008-08-21 Thread Peter N. M. Hansteen
ased on an analysis of observed needs and an actual specification, somewhere down the road. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network t

Re: A PF Certification - what do you think?

2008-07-10 Thread Peter GILMAN
Ken Gunderson <[EMAIL PROTECTED]> wrote: > Look what's happened to > FreeBSD - damned near unusable these days. funny - after using openbsd everywhere for years, i finally had to switch to freebsd on my laptop (tp a31) because things that had worked fine on previous versions of openbsd stopped w

A PF Certification - what do you think?

2008-07-10 Thread Peter N. M. Hansteen
ng but not limited to 'would it be more useful with a multi-level certification', and of course any input on what the task and skills spec should contain. [1] http://www.bsdcertification.org/index.php?NAV=FAQ#Q04 -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team htt

Re: New pf install on Freebsd seem to be a slow starter.

2008-07-10 Thread Peter N. M. Hansteen
until somewhere in your rc.local to fill in those addresses (say, with a script that checks if each name resolves, then adds the returned addresses to the table). Brittle, but with a fighting chance of working. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http

Re: Pass rule from subnet to external

2008-02-26 Thread Peter N. M. Hansteen
m' and 'to' keywords only denote source and destination addresses respectively. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network

Re: hoststated

2008-01-31 Thread Peter N. M. Hansteen
clear things up. Sorry. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Re: PF, limit remote clients by total bandwidth used over time

2007-12-29 Thread Peter N. M. Hansteen
), and I would think you're a lot closer to a solution that would fit the basic requirements, ie adding flexibility without adding clutter to the system at the same time. Just my EUR 0.02, and maybe better ideas will be had by morning. All the best, -- Peter N. M. Hansteen, member of the firs

"The Book of PF" exists, physical copies documented

2007-12-19 Thread Peter N. M. Hansteen
rrived and life's good :) One interesting factoid (fsvo) is that this happened within hours of the twenty-five thousandth unique visitor (since EuroBSDCon 2006 that is) hitting the book's predecessor, the online PF tutorial[4]. So happy hacking holidays everyone, [1] http://nostarch.com/

Re: PFW... ever used it?

2007-11-08 Thread Peter N. M. Hansteen
p://www.openbsd.org/faq/index.html>, and just to toot my own horn, there's word out that those *excellent* references are a little easier to take in usefully after you've spent some time browsing <http://home.nuug.no/~peter/pf/> (also nostarch.com may have the perfect xmas presen

Re: Need more performance (FreeBSD or OpenBSD)

2007-11-03 Thread Peter N. M. Hansteen
interested in the results. Once you have made a decision, > upgrading one is simpler than changing both. It would be interesting to hear any data that comes out of tests like that. That is, as long as the OP doesn't mind being a guinea pig. - P -- Peter N. M. Hansteen, member of th

Re: Need more performance (FreeBSD or OpenBSD)

2007-11-02 Thread Peter N. M. Hansteen
I'm also slightly curious about a direct comparison of FreeBSD vs OpenBSD performance on the same hardware. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.datadok.no/ http://www.nuug.no/ "Remember to set the evil bit on al

Re: linux/iptables/proxy arp to pf/redundant firewall

2007-10-24 Thread Peter N. M. Hansteen
ill don't see how a bridge would be totally desirable, bu then it's possible I'm just being incredibly dense. I think I'd need more information about your setup such as addresses and netmasks to offer any input on that. -- Peter N. M. Hansteen, member of the first RFC 1149

Re: linux/iptables/proxy arp to pf/redundant firewall

2007-10-24 Thread Peter N. M. Hansteen
it takes your main redundancy feature off the table. Why not just a carp/pfsync setup? -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.datadok.no/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network tra

Re: pfctl limits on number of tables

2007-10-19 Thread Peter N. M. Hansteen
The error reporting messages could possibly improved upon too. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.datadok.no/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Re: OpenCON 2007 // Call for Papers

2007-10-02 Thread Peter GILMAN
Ed wrote: > Dear ladies and gentlemen, > > OpenCON is the only conference fully dedicated to OpenBSD. Last year > edition was a great success and featured also the party for OpenBSD > 10th birthday, with project leader Theo de Raadt and a lot of > developers. More info here: http://2006.opencon.

Re: states handling

2007-09-22 Thread Peter N. M. Hansteen
centring view is really is the only logical perspective if you think of it. That's why I spend so much time hammering that in during the relatively basic PF tutorial I've been giving. (yes, the one at <http://home.nuug.no/~peter/pf/>). -- Peter N. M. Hansteen, member

Re: states handling

2007-09-21 Thread Peter N. M. Hansteen
out to the destination address. in simple environments it is possible to work around the problem by omitting direction (implicitly writing rules for both inbound and outbound traffic), ie block inet from 192.168.0.1 to 192.168.114.31 pass inet from 192.168.114.31 to 192.168.0.1 flags S/SA keep

Re: PF and forwarding to dmz

2007-07-05 Thread Peter N. M. Hansteen
. In the meantime, plain old keep state isn't too bad either. Cheers, -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://www.blug.linux.no/rfc1149/ http://www.datadok.no/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" d

Re: PF and forwarding to dmz

2007-07-04 Thread Peter N. M. Hansteen
tups where you need to pass traffic in on a specific interface (or interface group) and out on a some other specific interface or group, it's a different story of course, but PF lets you do the less complicated things in very straightforward ways. This is the kind of stuff I rant about ext

Re: Fair distribution of borrowed bandwidth with a lot of users

2007-04-17 Thread Peter N. M. Hansteen
e means is, you use "pass from queue foo" constructs -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://www.blug.linux.no/rfc1149/ http://www.datadok.no/ http://www.nuug.no/ "First, we kill all the spammers" The Usenet Bard, "Twice-forwarded t

Re: help in configuring icmp rules

2007-04-05 Thread Peter N. M. Hansteen
27; in your types list. If you use a list of icmp codes too, 'host-unr' would be a valid member of your list of codes. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://www.blug.linux.no/rfc1149/ http://www.datadok.no/ http://www.nuug.no/ "First, we

Re: DNS answers blocked?

2007-03-05 Thread Peter N. M. Hansteen
Jacques Beigbeder <[EMAIL PROTECTED]> writes: > But where is the trouble? Is there a better fix? hard to tell without taking a peek at your actual rule set, but could it be that you forgot "keep state" in the pass rules which let your name service queries through? -- P

Re: using pf to block multiple connections in a given time

2007-02-16 Thread Peter N. M. Hansteen
the connection. Can pf do this? The details differ slightly, but you can get something functionally equivalent using overload rules and a table you block. I have some musings on this in the tutorial[1], it does not cover all possible wrinkles but should be enough to get you started. [1] http://ho

Re: PF integrated solution

2007-01-21 Thread Peter N. M. Hansteen
f&sektion=8&manpath=OpenBSD+4.0 [3] http://home.nuug.no/~peter/pf/en/vegard.authpf.html -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://www.blug.linux.no/rfc1149/ http://www.datadok.no/ http://www.nuug.no/ "First, we kill all the spammers" Th

Featuritis: overload on transferred volumes, auto-expiring tables?

2007-01-07 Thread Peter N. M. Hansteen
such as table persist expire 24h meaning that table entries are removed when they have not been referenced during the last 24 hours. Oh well, it's late already. But it would be nice to hear any thoughts on this, including "shoot this down, quick!" [1] http://marc.theaimsgroup.com/?

Re: Squid 2.6 transparent proxy with pf

2006-12-21 Thread Peter N. M. Hansteen
of the world. > rdr pass on $int_if proto tcp from any to any port 80 -> $squid port 8080 I would supplement this with a 'no rdr' rule for the proxy generated traffic. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://www.blug.linux.no/rfc1149/

Re: Squid 2.6 transparent proxy with pf

2006-12-21 Thread Peter N. M. Hansteen
Dominik Zalewski <[EMAIL PROTECTED]> writes: > I have OpenBSD 4.0 firewall and I would like to redirect all outgoing http > requests to my squid web proxy. Daniel Hartmeier wrote about this a while back, his article can be found at http://www.benzedrine.cx/transquid.html --

Re: Any set ?

2006-12-15 Thread Peter N. M. Hansteen
al at http://home.nuug.no/~peter/pf/, specifically http://home.nuug.no/~peter/pf/en/tables.html, and of course man pfctl is your dearest friend :) -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://www.blug.linux.no/rfc1149/ http://www.datadok.no/ http://www.nuug.no

Re: ext_if, int_if?

2006-11-30 Thread Peter N. M. Hansteen
flags S/SA keep state pass inet proto tcp from any to $localnet port ssh flags S/SA keep state I have a semi-rant about these things in the tutorial[1], which I probably will be accused of plugging quite shamelessly at this point. [1] http://home.nuug.no/~peter/pf/, specifically about these matters

Re: ext_if, int_if?

2006-11-29 Thread Peter N. M. Hansteen
s block all pass from self to any keep state or pass from 10.12.14.0/24 to any port ssh keep state it's extremely flexible really. The reason you see interface name macros so often is that people tend to find them useful, but you can do without them entirely if you like, I suppose

OpenBSD ADSL connection problem

2006-11-15 Thread vas . peter
Hello, everyone! I'm not sure, if it is the good forum or not where I can post my problem, but I hope there is some people who met similar problems or have some good instructions as a solution. Sorry for a long letter. Till know I used Internet with ADSL, and an OpenBSD firewall separated my local

EuroBSDCon 2006 PF tutorial online

2006-11-15 Thread Peter N. M. Hansteen
As some of you may be aware, I presented a half day PF tutorial at EuroBSDCon in Milan. The manuscript is now online in several formats at http://home.nuug.no/~peter/pf/. This is a manuscript I've revisited on occasion over roughly the last two years, intended as a flash intro to the fu

Re: PF Table Size - Sanity Check

2006-11-07 Thread Peter N. M. Hansteen
; something that large? The limits are tuneable via pf.conf 'set limit' options. I forget what the default max table size is, but the pf.conf man page contains the magic to set it to 100,000 entries. Going from there should be straightforward. -- Peter N. M. Hansteen, member of the f

Re: lists vs tables

2006-09-22 Thread Peter N. M. Hansteen
w options which makes it easy to do operations on tables from the command line. So I suppose any set of addresses which conceivably could change more frequently than you would want to reload your entire rule set would be a prime candidate getting turned into a table. -- Peter N. M. Hansteen

Re: hfsc & cbq inaccuracy

2006-09-08 Thread Peter GILMAN
Michal Soltys <[EMAIL PROTECTED]> wrote: > > Those testes were with both enabled that's reassuring...

trouble with firewalls in series

2006-07-31 Thread Peter
I have a firewall running on my gateway. I also have a home mailserver on my lan on which I decided to place its own firewall. I am now getting disconnections from incoming SMTP traffic. I figure it is due to the TCP handshake not properly being set up but if someone can fill in the details

trouble with firewalls in series (update)

2006-07-31 Thread Peter
The problem was an error in my rules. It has been corrected but an auxilliary issue has surfaced. Due to limitations in hardware this second firewalled host has two IP addresses on the same subnet. I would like requests to certain ports to exit on a particular interface. How do I do that? For

shell script troubles using expr ("non-numeric argument")

2006-07-27 Thread Peter
I am writing a shell script to handle simple IP accounting and I'm getting an error I cannot solve. Here is the pertinent snippet: PORT_IN=$(pfctl -sl | grep $i | grep $LABEL | cut -d ' ' -f 9)# bytes PORT_IN=$(echo "scale=3; $PORT_IN / 1024" | bc) # kilobytes PORT_IN_SUM=$(cat

Re: pf "default deny" compile-time option?

2006-07-19 Thread Peter N. M. Hansteen
run -current on something mission critical a continent away, 'glutton for punishment' comes to mind. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://www.blug.linux.no/rfc1149/ http://www.datadok.no/ http://www.nuug.no/ "First, we kill all the spa

Re: getting started with pfstat

2006-07-13 Thread Peter
--- Daniel Hartmeier <[EMAIL PROTECTED]> wrote: > On Thu, Jul 13, 2006 at 11:07:46AM -0400, Peter wrote: > > > I have installed the pfstat 1.7 package on my 3.8 system. The > trouble > > is that I do not get any data being graphed. Here is my test > setup: > &

getting started with pfstat

2006-07-13 Thread Peter
th (i.e. every one minute as opposed to every five minutes)? Peter __ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com

'route to' question

2006-07-05 Thread Peter Blair
Hello lists! (sorry if cross-list posting is frowned upon) I'm setting up a BSD/pf machine that will be working as a binat firewall for a number of hosts on two /28 subnets belonging to the same co-location provider. The BSD machine is already live, working hard for one subnet, and I don't have

Re: Open BSD 3.9 unable to send email with attachment thru pf

2006-06-27 Thread Peter N. M. Hansteen
king it without timing out, and so on. There are several more ways to misconfigure a machine so it will produce the rather bizarre symptoms you are describing, but from the information you are volunteering it's pretty much impossible to tell what is causing the situation. -- Peter N. M. Hanste

10 Interface Router - How to efficently pf?

2006-05-08 Thread Peter Wood
is is my first large scale pf configuration. My full config is at: http://narwar.net/~peter/pf.conf Note that traffic to lo0 is currently just passed as I couldn't figure out what to do with it. Am I thinking about this the wrong way, should I basically have a pass in set from each subn

Re: PF inadequacy: queue download

2006-05-02 Thread Peter N. M. Hansteen
ous goodness of your wished-for feature does not convince, you should consider the possibility that a) your idea isn't actually that obviously good or b) you need to work a bit more on that explanation. Abuse and name-calling never helps your case, ever. -- Peter N. M. Hansteen, mem

Re: Passive FTP error after restart machine..

2006-04-27 Thread Peter N. M. Hansteen
st its controlling terminal due to a reboot of a putty.exe equipped machine elsewhere, it all started working again in that particular case. Given the stability of the platform running putty.exe, this has happened more than once. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation t

Re: Migration document for people coming from IPFilter?

2006-04-11 Thread Peter N. M. Hansteen
2.168.1.101 port 6502 > rdr tx1 1.2.3.3/32 port 6503 -> 192.168.1.122 port 6503 These are ordinary redirects as far as I can see, so would carry over with minor adjustments. Hope this helps, [1] the tutorial is a work in progress, with a reasonably up to date version posted at http://w

Re: PF and label expansion limitations

2006-04-06 Thread Peter
--- Per-Olov Sj�holm <[EMAIL PROTECTED]> wrote: > On Thursday 06 April 2006 01.03, Peter wrote: > > --- Per-Olov Sj�holm <[EMAIL PROTECTED]> wrote: > > > The PF rule... > > > pass in quick on $EXTERNAL_INT inet from any to $COLOC_IPS_1 &g

Re: PF and label expansion limitations

2006-04-05 Thread Peter
--- Per-Olov Sj�holm <[EMAIL PROTECTED]> wrote: > The PF rule... > pass in quick on $EXTERNAL_INT inet from any to $COLOC_IPS_1 label > "TEST:$dstaddr#" keep state > > Gives a label like > TEST:65.45.128.128/25# 230 3099 1511793 1370 148914 1729 1362879 > > > Is there an easy way to do e

Re: pf; XP firewall; and MS Remote Desktop

2006-04-05 Thread Peter
--- Don Boling <[EMAIL PROTECTED]> wrote: > On 4/5/06, Peter <[EMAIL PROTECTED]> wrote: > > I have a user that is on WinXP. She uses Microsoft's Remote > Desktop to > > connect to a remote server (TCP port 3389). I have installed > OpenBSD > >

pf; XP firewall; and MS Remote Desktop

2006-04-05 Thread Peter
ence and the latency is going to happen again in which case I am asking people what do they think I should look at? I have since begun making long term tcpdump captures using pflog0. Thanks, Peter __ Do You Yahoo!? Tired of spam? Yahoo! Ma

Re: Migration document for people coming from IPFilter?

2006-04-04 Thread Peter N. M. Hansteen
[EMAIL PROTECTED] writes: > Thanks Peter and mouss for the replies. Oh, you're welcome, > But I'm still puzzled. I read the description of the rdr directive a > number of times and looked at some of the examples but it's still not > clear to me how the above pr

Re: Stuck with FTP rules

2006-04-03 Thread Peter
--- IMS <[EMAIL PROTECTED]> wrote: > Hi all > > I try to write FTP rules with ftp-proxy. > However after try for serveral hours.. > It isn't work.. It depends what kind of FTP you are looking at. Most FTP clients these days use passive FTP. In this case, you do not need ftp-proxy at all. You

Re: Migration document for people coming from IPFilter?

2006-04-02 Thread Peter N. M. Hansteen
[EMAIL PROTECTED] (mouss) writes: > map != rdr. ipf != pf. .? -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://www.blug.linux.no/rfc1149/ http://www.datadok.no/ http://www.nuug.no/ "First, we kill all the spammers" The Usenet Bard, "Twice-forw

Re: Migration document for people coming from IPFilter?

2006-04-02 Thread Peter N. M. Hansteen
ipsec/tcp > map $ext_if 192.168.10.0/24 -> 1.2.3.4/32 portmap tcp/udp 1025:65000 > map $ext_if 192.168.10.0/24 -> 1.2.3.4/32 browsing the IPF howto briefly, I think you should be able to get those done via rdr constructs and matching pass rules. The finer details escape me, though.

Re: Confuse with PF rules..

2006-04-01 Thread Peter N. M. Hansteen
port http keep state would serve you better in the end. My rant about this is at http://www.bgnett.no/~peter/pf/en/basicgw.html (part of a PF tutorial). -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://www.blug.linux.no/rfc1149/ http://www.datadok.no/ http://www.n

Re: Confuse with PF rules..

2006-03-31 Thread Peter N. M. Hansteen
probably want a NAT rule in your config as well. - have you enabled gatewaying (sysctl net.inet.ip.forwarding=1)? -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://www.blug.linux.no/rfc1149/ http://www.datadok.no/ http://www.nuug.no/ "First, we kill all the

Firewalling with PF tutorial, March 2006 update

2006-03-25 Thread Peter N. M. Hansteen
, please let me know. Comments of all kinds are welcome. And yes, the manuscript is set to evolve a bit further for BSDCan and SANE, those updates will appear on-line, BSD licensed, after the conferences too. The files are at http://www.bgnett.no/~peter/pf/, or can be accessed directly as

Re: ftp-proxy, and one nic: oh my...

2006-03-15 Thread Peter N. M. Hansteen
you are not making debugging any easier. you could try my tutorial at http://www.bgnett.no/~peter/pf/ for a gentle walkthrough. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://www.blug.linux.no/rfc1149/ http://www.datadok.no/ http://www.nuug.no/ "First

Re: Solution Request: I need to initiate outbound PPTP requests thru FreeBSD firewall

2006-03-12 Thread Peter N. M. Hansteen
mes? This is certainly not a comprehensive analysis, but do look into the logic issues here. The readability issues are probably byproducts of using a GUI tool, so I won't beat you over the head with them just yet. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation t

Re: Solution Request: I need to initiate outbound PPTP requests thru FreeBSD firewall

2006-03-11 Thread Peter N. M. Hansteen
PN" for something or other thought of some other way to do what they needed. (Microsoft - no, there's always an easier way :)) -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://www.blug.linux.no/rfc1149/ http://www.datadok.no/ http://www.nuug.no/ "

Re: PF Feature request: graceful handling of non-lookupable hosts.

2006-02-27 Thread Peter N. M. Hansteen
ution unless handled properly. Done right it sounds rather attractive though. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://www.blug.linux.no/rfc1149/ http://www.datadok.no/ http://www.nuug.no/ "First, we kill all the spammers" The Usenet Bard, "

Re: Debugging/troubleshooting rule sets.

2006-02-27 Thread Peter N. M. Hansteen
icial PF docs a bit more accessible after spending some time with my PF tutorial at http://www.bgnett.no/~peter/pf/ (see events.html at the openbsd site for live performances of a slightly revised version). "debugging PF rule sets" might actually be a good tutorial topic. Noted for lat

Re: PF Feature request: graceful handling of non-lookupable hosts.

2006-02-27 Thread Peter N. M. Hansteen
ral admin checklist. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://www.blug.linux.no/rfc1149/ http://www.datadok.no/ http://www.nuug.no/ "First, we kill all the spammers" The Usenet Bard, "Twice-forwarded tales" 20:11:56 delilah spamd[26905]:

Re: OpenBSD PF firewall on linux

2006-02-18 Thread Peter N. M. Hansteen
FreeBSD (lots more packages available). [1] For some odd reason these messages were not as easy to find as I had thought, but I'm pretty sure they're in the archives somewhere -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://www.blug.linux.n

Flush a state for a particular host in block rule

2006-02-09 Thread Peter W. Merrit
one out. Thanks in Advance Peter

Re: pf and nat with labels for bandwidth accounting

2006-02-07 Thread Peter
--- [EMAIL PROTECTED] wrote: > Hi all > > I hope this has not been asked millions of times... becasue if it has I > am beyond help... since I cannot find the solution. Upgrade to 3.8. You get two more columns which do track ALL traffic. # pfctl -sl | grep tcp:80 inbound - tcp:80 -> 1 4 184 2

Re: [OT] pf and vpn

2006-02-06 Thread Peter
--- David Powers <[EMAIL PROTECTED]> wrote: > I highly recommend looking into openvpn as an alternative. If you have > control of both ends and don't have to work to inter operate with an > existing IPSEC implementation then it is vastly easier to setup and > maintain. > > -David > > Travis

Re: ssh bruteforce attempts and timeout of table w/ persist keyword

2006-02-02 Thread Peter N. M. Hansteen
(interface) notation is supposed to take care of? as in ext_if = "tun0" # macro for external interface - use tun0 for PPPoE int_if = "xl1" # macro for internal interface # ext_if IP address could be dynamic, hence ($ext_if) nat on $ext_if from $int_if:network to any -> ($ext

Re: ssh bruteforce attempts and timeout of table w/ persist keyword

2006-02-02 Thread Peter N. M. Hansteen
ports system. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://www.blug.linux.no/rfc1149/ http://www.datadok.no/ http://www.nuug.no/ "First, we kill all the spammers" The Usenet Bard, "Twice-forwarded tales"

Re: PF Connection Throttling (prevent DoS)

2006-01-22 Thread Peter N. M. Hansteen
ription in http://www.bgnett.no/~peter/pf/en/bruteforce.html is written mainly with SSH bruteforcers in mind, but with a few trivial adjustments would apply equally well to SMTP. On the other hand, I would risk a wild guess that the bots all run a certain family of operating systems, in which cas

[OT] pf and vpn

2006-01-17 Thread Peter
communications. Why is that? The provided rc.vpn script does this without explanation. 2. What is the use of forcing IP-in-IP (-forcetunnel) when setting up an SA? The vpn manpage example does this without explanation. -- Peter

RE: viewing pf rules in tcpdump output

2006-01-16 Thread Peter
--- "Melameth, Daniel D." <[EMAIL PROTECTED]> wrote: > Peter wrote: > > Question: Why does tcpdump show pf rules when I use the pflog0 > > interface in combination with the -e switch (link layer)? It's a > > fantastic feature but it seems like an odd w

viewing pf rules in tcpdump output

2006-01-14 Thread Peter
0x00001 -- Peter __ Find your next car at http://autos.yahoo.ca

Re: Recording statistics for PF...

2006-01-06 Thread Peter
--- Forrest Aldrich <[EMAIL PROTECTED]> wrote: > Coming from FreeBSD's ipfw2, I've been accustomed to having a timestamp > (ie: ipfw -t) that allowed me to measure "hits" on a given > IP/block/rule. > > This isn't available with PF (though I think it would be a good idea). > > I maintain (as a

Re: graphing pf stats

2006-01-03 Thread Peter
--- [EMAIL PROTECTED] wrote: > We use Cacti, Net-SNMP, and several Perl scripts to monitor our OpenBSD > firewalls. > > https://noc.ece.uprm.edu/cacti/graph_view.php?action=tree&tree_id=2&hide=0&branch_id=734 > > Pablo > > > > I have written an IP accounting system using pf labels. It runs e

graphing pf stats

2006-01-01 Thread Peter
matter. -- Peter __ Find your next car at http://autos.yahoo.ca

Re: Problems with BLOCK an RDR/tables not working...

2005-12-26 Thread Peter
t_if inet proto tcp from any to any port { $tcp_services } > \ > modulate state > > pass in on $ext_if inet proto tcp from any to any port { 80, 443 } > modulate state > > > > pass in on $ext_if inet proto udp all keep state > > pass in on $ext_if inet prot

Re: dumbfounded

2005-12-22 Thread Peter
--- Cédric Berger <[EMAIL PROTECTED]> wrote: > Peter wrote: > > Can someone please tell me how my webserver LEO is able to respond to > > requests? Don't I need to specify an outgoing rule (pass out) for > > replies? > > > Your RDR rule implicitely

dumbfounded

2005-12-21 Thread Peter
Can someone please tell me how my webserver LEO is able to respond to requests? Don't I need to specify an outgoing rule (pass out) for replies? nat on $EXT from $LAN_clients to any -> $EXT rdr on $EXT proto tcp from any to ($EXT) port 80 -> $LEO port 80 block in on $EXT all pass in o

Re: pf won't pass some port 53 traffic even when asked nicely to

2005-12-19 Thread Peter Hessler
On 19 Dec 2005 14:33:27 -0800 "Jonathan Rogers" <[EMAIL PROTECTED]> wrote: : The think I can't understand is that I'm explicitly passing this kind : of traffic: : :pass in quick on $dmz_if inet proto tcp from 192.168.3.0/26 to any : port { 53 80 } : keep state flags S/SA label "pass

Re: excluding a port from a range

2005-12-11 Thread Peter
or > subtract the statistics of the narrow rule (matching that one port) > from the more broad rule. Or, you could make the narrow rule come > first and use "quick" to prevent it from matching the

  1   2   3   >