Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 25 Apr 2021 08:56:49 +0300
From:      =?UTF-8?B?w5Z6a2FuIEtJUklL?= <ozkan.kirik@gmail.com>
To:        freebsd-pf@freebsd.org, Kristof Provost <kp@freebsd.org>
Subject:   pf - SCTP ports are not allowed in filter rules.
Message-ID:  <CAAcX-AFLLPOuLws%2B=qFYp9KXNqD_cYWpA3zbDr2WOgNLMnKRKg@mail.gmail.com>

next in thread | raw e-mail | index | archive | help
Hi,

SCTP protocol header has src port and dst port fields. But pf doesn't
supports.

# echo "pass  log (to pflog0) quick   proto SCTP from  any to any port
13873" | pfctl -f -
stdin:1: port only applies to tcp/udp
stdin:1: skipping rule due to errors
stdin:1: rule expands to no valid combination
pfctl: Syntax error in config file: pf rules not loaded
#

I tried to write same rule with ipfw. It works.

# ipfw add 200 allow sctp from any to any 13873
00200 allow sctp from any to any 13873

Do I have a mistake or filtering for SCTP ports are not supported by pf ?
Is it possible to fix ?

Best Regards
Ozkan



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CAAcX-AFLLPOuLws%2B=qFYp9KXNqD_cYWpA3zbDr2WOgNLMnKRKg>