From owner-freebsd-questions@FreeBSD.ORG Tue May 18 12:28:56 2010 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 465AB1065676 for ; Tue, 18 May 2010 12:28:56 +0000 (UTC) (envelope-from mexas@bristol.ac.uk) Received: from dirj.bris.ac.uk (dirj.bris.ac.uk [137.222.10.78]) by mx1.freebsd.org (Postfix) with ESMTP id 059048FC08 for ; Tue, 18 May 2010 12:28:55 +0000 (UTC) Received: from ncsc.bris.ac.uk ([137.222.10.41]) by dirj.bris.ac.uk with esmtp (Exim 4.69) (envelope-from ) id 1OELuo-0005Gl-Mz for freebsd-questions@freebsd.org; Tue, 18 May 2010 13:28:54 +0100 Received: from mech-cluster241.men.bris.ac.uk ([137.222.187.241]) by ncsc.bris.ac.uk with esmtpsa (TLSv1:AES256-SHA:256) (Exim 4.67) (envelope-from ) id 1OELuo-00067e-KI for freebsd-questions@freebsd.org; Tue, 18 May 2010 13:28:54 +0100 Received: from mech-cluster241.men.bris.ac.uk (localhost [127.0.0.1]) by mech-cluster241.men.bris.ac.uk (8.14.4/8.14.4) with ESMTP id o4ICSrY2007716 for ; Tue, 18 May 2010 13:28:53 +0100 (BST) (envelope-from mexas@bristol.ac.uk) Received: (from mexas@localhost) by mech-cluster241.men.bris.ac.uk (8.14.4/8.14.4/Submit) id o4ICSr8V007715 for freebsd-questions@freebsd.org; Tue, 18 May 2010 13:28:53 +0100 (BST) (envelope-from mexas@bristol.ac.uk) X-Authentication-Warning: mech-cluster241.men.bris.ac.uk: mexas set sender to mexas@bristol.ac.uk using -f Date: Tue, 18 May 2010 13:28:53 +0100 From: Anton Shterenlikht To: freebsd-questions@freebsd.org Message-ID: <20100518122852.GA6441@mech-cluster241.men.bris.ac.uk> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.5.20 (2009-06-14) Subject: ipfilter rules question X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 18 May 2010 12:28:56 -0000 I'm using ipfilter on -current. Here's a fragment of the outgoing rules: # ipfstat -on *skip* @14 pass out quick on bge0 proto udp from any to any port = 8649 keep state *skip* @18 pass out log first quick on bge0 all And I see these ipmon entries in /var/log/ipfilter.log: ipmon[765]: 00:01:04.242290 bge0 @0:18 p 137.222.187.221,10280 -> 239.2.11.71,8649 PR udp len 20 96 OUT multicast ipmon[765]: 00:01:09.702391 5x bge0 @0:18 p 137.222.187.221,10280 -> 239.2.11.71,8649 PR udp len 20 92 OUT multicast ipmon[765]: 00:01:24.062025 7x bge0 @0:18 p 137.222.187.221,10280 -> 239.2.11.71,8649 PR udp len 20 92 OUT multicast I don't understand why these packets are not sent via rule 14. Is rule 14 not matched? Or I'm missing someting else? many thanks anton -- Anton Shterenlikht Room 2.6, Queen's Building Mech Eng Dept Bristol University University Walk, Bristol BS8 1TR, UK Tel: +44 (0)117 331 5944 Fax: +44 (0)117 929 4423