RE: pf and Microsoft Exchange IMAPS

2005-11-17 Thread Raphael GRUNDRICH
hello, Finally Daniel had the last word : "A quick first guess would be that the IMAP server is not routing its replies through the pf box (i.e. the default gateway setting on the IMAP server is wrong)." By changing the default gw of my IMAP Exchange server with my testing PF Firewall, the con

Re: pf and Microsoft Exchange IMAPS

2005-11-17 Thread Jon Hart
On Wed, Nov 16, 2005 at 04:34:24PM +0100, Raphael GRUNDRICH wrote: > Hello, > > I'm trying to redirected outside traffic to internal Exchange Server > using IMAPS protocol : > > rdr on $ext_if proto tcp from any to any port 993 -> 192.168.1.1 > pass in quick on $ext_if \ > proto tcp \ >

Re: pf and Microsoft Exchange IMAPS

2005-11-17 Thread Daniel Hartmeier
On Thu, Nov 17, 2005 at 11:37:55AM +0100, Raphael GRUNDRICH wrote: > Can you say to me why the best I can have is : > PROXY:DST (pfctl -ss) > > shouldn't get > ESTABLISHED:ESTABLISHED > like a www,ssh, .. connection ? That means you're using synproxy and that pf has completed the TCP handsha

RE: pf and Microsoft Exchange IMAPS

2005-11-17 Thread Raphael GRUNDRICH
EMAIL PROTECTED] Envoyé : jeudi 17 novembre 2005 10:03 À : Raphael GRUNDRICH Cc : pf@benzedrine.cx; Peter N. M. Hansteen; [EMAIL PROTECTED] Objet : Re: pf and Microsoft Exchange IMAPS On Thu, Nov 17, 2005 at 09:41:29AM +0100, Raphael GRUNDRICH wrote: > (I make the test on internal interface so do

Re: pf and Microsoft Exchange IMAPS

2005-11-17 Thread Peter N. M. Hansteen
> I'm trying to redirected outside traffic to internal Exchange Server using > IMAPS protocol : when you manage to get it working, I would be interested in hearing about it. it might be a useful addition to my PF tutorial. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation te

Re: pf and Microsoft Exchange IMAPS

2005-11-17 Thread Daniel Hartmeier
On Thu, Nov 17, 2005 at 09:41:29AM +0100, Raphael GRUNDRICH wrote: > (I make the test on internal interface so don't be surprise by the network > address, 1.236 is my internal firewall address, 1.233 is my outlook client > address) And that's the problem, you can't test it like that, see Red

RE: pf and Microsoft Exchange IMAPS

2005-11-17 Thread Raphael GRUNDRICH
[EMAIL PROTECTED] Envoyé : mercredi 16 novembre 2005 17:29 À : Raphael GRUNDRICH Objet : Re: pf and Microsoft Exchange IMAPS "Raphael GRUNDRICH" <[EMAIL PROTECTED]> writes: > pass in quick on $ext_if \ > proto tcp \ > from any to 192.168.1.1 port imaps flags

Re: pf and Microsoft Exchange IMAPS

2005-11-16 Thread Greg Hennessy
On 16 Nov 2005 08:40:31 -0800, [EMAIL PROTECTED] (Peter N. M. Hansteen) wrote: >"Raphael GRUNDRICH" <[EMAIL PROTECTED]> writes: > >> rdr on $ext_if proto tcp from any to any port 993 -> 192.168.1.1 >> pass in quick on $ext_if \ >> proto tcp \ >> from any to 192.168.1.15 port imap

Re: pf and Microsoft Exchange IMAPS

2005-11-16 Thread Karl O. Pinc
The next step might be a tcpdump on the external interface to watch the traffic and see that it's not doing something suprising on some other port or something. On 11/16/2005 10:20:01 AM, Raphael GRUNDRICH wrote: Errata : pass in quick on $ext_if \ proto tcp \ from any to 192.

RE: pf and Microsoft Exchange IMAPS

2005-11-16 Thread Raphael GRUNDRICH
di 16 novembre 2005 17:16 À : Raphael GRUNDRICH Cc : pf@benzedrine.cx Objet : Re: pf and Microsoft Exchange IMAPS "Raphael GRUNDRICH" <[EMAIL PROTECTED]> writes: > rdr on $ext_if proto tcp from any to any port 993 -> 192.168.1.1 > pass in quick on $ext_if \ >

Re: pf and Microsoft Exchange IMAPS

2005-11-16 Thread Peter N. M. Hansteen
"Raphael GRUNDRICH" <[EMAIL PROTECTED]> writes: > rdr on $ext_if proto tcp from any to any port 993 -> 192.168.1.1 > pass in quick on $ext_if \ > proto tcp \ > from any to 192.168.1.15 port imaps flags S/SA synproxy state assuming the exchange server is somewhere in $int_if:netw

pf and Microsoft Exchange IMAPS

2005-11-16 Thread Raphael GRUNDRICH
Hello, I'm trying to redirected outside traffic to internal Exchange Server using IMAPS protocol : rdr on $ext_if proto tcp from any to any port 993 -> 192.168.1.1 pass in quick on $ext_if \ proto tcp \ from any to 192.168.1.15 port imaps flags S/SA synproxy state Outlook clie