Re: statefull matching vs. local inet6

2006-08-04 Thread Max Laier
On Friday 04 August 2006 13:13, Fabian Keil wrote: > Max Laier <[EMAIL PROTECTED]> wrote: > > On a box running sshd (or something listening on an inet6 tcp port) > > load the following ruleset: > > > > pass quick on lo0 all > > pass quick on bge0 inet all > > block drop log all > > pass in log-all

Re: statefull matching vs. local inet6

2006-08-04 Thread Fabian Keil
Max Laier <[EMAIL PROTECTED]> wrote: > On a box running sshd (or something listening on an inet6 tcp port) > load the following ruleset: > > pass quick on lo0 all > pass quick on bge0 inet all > block drop log all > pass in log-all on bge0 inet6 proto tcp from any to 3000::1 port = ssh \ > flag

statefull matching vs. local inet6

2006-08-03 Thread Max Laier
Hi, can somebody try the following on a recent OpenBSD box? I'm in the middle of reshuffling my hardware (for a couple of month now *sigh*) and don't have a test setup handy. Thanks. On a box running sshd (or something listening on an inet6 tcp port) load the following ruleset: pass quick o