From nobody Fri Aug 20 19:01:41 2021 X-Original-To: freebsd-pf@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id E38BD177C0A6 for ; Fri, 20 Aug 2021 19:01:53 +0000 (UTC) (envelope-from ozkan.kirik@gmail.com) Received: from mail-ua1-x92b.google.com (mail-ua1-x92b.google.com [IPv6:2607:f8b0:4864:20::92b]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "GTS CA 1O1" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4GrrbN67Ctz4prx for ; Fri, 20 Aug 2021 19:01:52 +0000 (UTC) (envelope-from ozkan.kirik@gmail.com) Received: by mail-ua1-x92b.google.com with SMTP id a4so4506592uae.6 for ; Fri, 20 Aug 2021 12:01:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:from:date:message-id:subject:to; bh=jy5KW/6d950/ko86KBCtQJwd4Gca+Ie+mZeu1/0VovA=; b=ulW1ePpl8zSeaH735LUF89ElUYx+IVKCF1aMC+6NAtOv8305bsRXYdIXJLP5GKQdIC b46x0xOaPl+RqNbQUOCdsG42DdTfpiwJ2UxxCG3Z08rb+l4wqzJjWlGnAG1D0WnoQNdB A2WHCzUUIAV5wVpi3tIl1F5fO8FQTMnV4RuBux7qkpyf80ml0w6WgCpXZ3rgrNcZkKER aV5KqP7p+581a48lAnCR9pXQEo0Am/rupjS+4ZM+OeLROU8fT6/x5er6MyvHxKtXA4sJ apOUv7cWNaGSTtf2G3W66HSe1ozKqcirgg2f/jqmdc5tcL+ew2rvhOxQXeC9cJjtD2qX MJ3w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=jy5KW/6d950/ko86KBCtQJwd4Gca+Ie+mZeu1/0VovA=; b=Ds/nF7d4Y8335y9B0Pp84fWMBsFsEgwnNutspVscF0n53kS8mAGjF0SMgi2XMTQJt2 9yokv3WI9BAG1lzNQNuBO9Zmco9KEKYngTtNDrhHl7KadM2ejKm6mlCwhJJUyn+0YJvp +28O9vkzq2DfOcmJ/9QLSgtwarwRF9SHFI2Hl0eRMDdHhTElGIUJ0mOhQVqcUpYRcNGw LHvp4e4MCyeLCweGFN2I/cFSfm7LMaQ0aWUREBVNCMvwELbuGQ/B7JXs/OPIYIm6PrhB c2g9IDuSFSf93pn5efDB/VF4ALHPS8KH0d4yjU97NeE3nYYw8Gab88emzxtyshz7G9cG RYsA== X-Gm-Message-State: AOAM530mqe1StprNRCFfsNiWCHtc4MnLeOzxgP8uW8a/VBqXaDPmUwIT QBsHxJL29A3fBdytD12uCLF7BVsaB6PiHH0cmoPsT6fK5h/wGg== X-Google-Smtp-Source: ABdhPJyhvOIMk0OIZMBlR5VLgqmFEGlYq3tHB1NFOg8hGmWk0psbj6VCwwc0PIuRybVpKpFPdGDPBJL2Fzc5MqwNomU= X-Received: by 2002:ab0:7681:: with SMTP id v1mr17182840uaq.62.1629486112009; Fri, 20 Aug 2021 12:01:52 -0700 (PDT) List-Id: Technical discussion and general questions about packet filter (pf) List-Archive: https://lists.freebsd.org/archives/freebsd-pf List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-pf@freebsd.org X-BeenThere: freebsd-pf@freebsd.org MIME-Version: 1.0 From: =?UTF-8?B?w5Z6a2FuIEtJUklL?= Date: Fri, 20 Aug 2021 22:01:41 +0300 Message-ID: Subject: pfctl -k id not working To: freebsd-pf@freebsd.org Content-Type: multipart/alternative; boundary="000000000000df711505ca024c45" X-Rspamd-Queue-Id: 4GrrbN67Ctz4prx X-Spamd-Bar: -- Authentication-Results: mx1.freebsd.org; dkim=pass header.d=gmail.com header.s=20161025 header.b=ulW1ePpl; dmarc=pass (policy=none) header.from=gmail.com; spf=pass (mx1.freebsd.org: domain of ozkankirik@gmail.com designates 2607:f8b0:4864:20::92b as permitted sender) smtp.mailfrom=ozkankirik@gmail.com X-Spamd-Result: default: False [-2.29 / 15.00]; FREEMAIL_FROM(0.00)[gmail.com]; R_SPF_ALLOW(-0.20)[+ip6:2607:f8b0:4000::/36]; TO_DN_NONE(0.00)[]; MID_RHS_MATCH_FROMTLD(0.00)[]; DKIM_TRACE(0.00)[gmail.com:+]; DMARC_POLICY_ALLOW(-0.50)[gmail.com,none]; NEURAL_HAM_SHORT(-1.00)[-1.000]; FROM_EQ_ENVFROM(0.00)[]; MIME_TRACE(0.00)[0:+,1:+,2:~]; FREEMAIL_ENVFROM(0.00)[gmail.com]; ASN(0.00)[asn:15169, ipnet:2607:f8b0::/32, country:US]; TAGGED_FROM(0.00)[]; R_MIXED_CHARSET(0.71)[subject]; DWL_DNSWL_NONE(0.00)[gmail.com:dkim]; ARC_NA(0.00)[]; NEURAL_HAM_MEDIUM(-1.00)[-1.000]; R_DKIM_ALLOW(-0.20)[gmail.com:s=20161025]; FROM_HAS_DN(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; NEURAL_HAM_LONG(-1.00)[-1.000]; MIME_GOOD(-0.10)[multipart/alternative,text/plain]; PREVIOUSLY_DELIVERED(0.00)[freebsd-pf@freebsd.org]; RCPT_COUNT_ONE(0.00)[1]; RCVD_IN_DNSWL_NONE(0.00)[2607:f8b0:4864:20::92b:from]; HTTP_TO_IP(1.00)[]; RCVD_COUNT_TWO(0.00)[2]; RCVD_TLS_ALL(0.00)[] X-ThisMailContainsUnwantedMimeParts: Y --000000000000df711505ca024c45 Content-Type: text/plain; charset="UTF-8" Hi, I'm trying to kill a single state using state id. But even state exists, no (0) states are killed. I'm using FreeBSD stable/12 0f97f2a1857a (Jul 26) build. Outputs are below: root@freebsd:/ # pfctl -ss -vvv | tail -5 all tcp 10.255.4.134:60684 -> 10.2.3.10:443 ESTABLISHED:ESTABLISHED [3857528462 + 256] wscale 7 [2278827950 + 1117184] wscale 9 age 1002336:42:40, expires in 252932:33:04, 250675:343858 pkts, 18984576:362136695 bytes, anchor 1308884992, rule 419430400 id: effe296100000018 creatorid: e9c975c1 gateway: 0.0.0.0 origif: ix0.167 root@freebsd:/ # pfctl -k id -k effe296100000018 killed 0 states root@freebsd:/ # pfctl -ss -vvv | tail -5 all tcp 10.255.4.134:60684 -> 10.2.3.10:443 ESTABLISHED:ESTABLISHED [1005467278 + 256] wscale 7 [2245470126 + 1117184] wscale 9 age 60966:41:04, expires in 280894:34:40, 250677:343861 pkts, 18984766:362137617 bytes, anchor 1308884992, rule 419430400 id: effe296100000018 creatorid: e9c975c1 gateway: 0.0.0.0 origif: ix0.167 is it possible to fix it? Regards --000000000000df711505ca024c45-- From nobody Sun Aug 22 18:58:09 2021 X-Original-To: pf@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id F3C2517781D2 for ; Sun, 22 Aug 2021 18:58:15 +0000 (UTC) (envelope-from shuriku@shurik.kiev.ua) Received: from mail.flex-it.com.ua (mail.flex-it.com.ua [193.239.74.7]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 4Gt4QG6sq5z3vfF for ; Sun, 22 Aug 2021 18:58:14 +0000 (UTC) (envelope-from shuriku@shurik.kiev.ua) Received: from [93.183.208.50] (helo=thinkpad.flex-it.com.ua) by mail.flex-it.com.ua with esmtpsa (TLS1.3) tls TLS_AES_128_GCM_SHA256 (Exim 4.94.2 (FreeBSD)) (envelope-from ) id 1mHsfW-0009N2-GL for pf@freebsd.org; Sun, 22 Aug 2021 21:58:06 +0300 Subject: Re: pfctl -k id not working To: pf@freebsd.org References: From: Oleksandr Kryvulia Message-ID: <437ea6f8-a93f-4650-1e94-c52110d328e7@shurik.kiev.ua> Date: Sun, 22 Aug 2021 21:58:09 +0300 User-Agent: Mozilla/5.0 (X11; FreeBSD amd64; rv:78.0) Gecko/20100101 Thunderbird/78.13.0 List-Id: Technical discussion and general questions about packet filter (pf) List-Archive: https://lists.freebsd.org/archives/freebsd-pf List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-pf@freebsd.org X-BeenThere: freebsd-pf@freebsd.org MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit Content-Language: ru X-Rspamd-Queue-Id: 4Gt4QG6sq5z3vfF X-Spamd-Bar: / Authentication-Results: mx1.freebsd.org; dkim=none; dmarc=none; spf=pass (mx1.freebsd.org: domain of shuriku@shurik.kiev.ua designates 193.239.74.7 as permitted sender) smtp.mailfrom=shuriku@shurik.kiev.ua X-Spamd-Result: default: False [0.20 / 15.00]; RCVD_VIA_SMTP_AUTH(0.00)[]; ARC_NA(0.00)[]; MID_RHS_MATCH_FROM(0.00)[]; FROM_HAS_DN(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; R_SPF_ALLOW(-0.20)[+mx]; MIME_GOOD(-0.10)[text/plain]; TO_DN_NONE(0.00)[]; DMARC_NA(0.00)[shurik.kiev.ua]; NEURAL_SPAM_MEDIUM(0.69)[0.692]; RCPT_COUNT_ONE(0.00)[1]; NEURAL_HAM_LONG(-0.64)[-0.644]; NEURAL_SPAM_SHORT(0.45)[0.454]; FROM_EQ_ENVFROM(0.00)[]; R_DKIM_NA(0.00)[]; MIME_TRACE(0.00)[0:+]; ASN(0.00)[asn:35297, ipnet:193.239.72.0/22, country:UA]; RCVD_COUNT_TWO(0.00)[2]; RCVD_TLS_ALL(0.00)[] X-ThisMailContainsUnwantedMimeParts: N 20.08.21 22:01, Özkan KIRIK пишет: > Hi, > > I'm trying to kill a single state using state id. But even state exists, no > (0) states are killed. > > I'm using FreeBSD stable/12 0f97f2a1857a (Jul 26) build. Outputs are below: > > root@freebsd:/ # pfctl -ss -vvv | tail -5 > all tcp 10.255.4.134:60684 -> 10.2.3.10:443 ESTABLISHED:ESTABLISHED > [3857528462 + 256] wscale 7 [2278827950 + 1117184] wscale 9 > age 1002336:42:40, expires in 252932:33:04, 250675:343858 pkts, > 18984576:362136695 bytes, anchor 1308884992, rule 419430400 > id: effe296100000018 creatorid: e9c975c1 gateway: 0.0.0.0 > origif: ix0.167 > > root@freebsd:/ # pfctl -k id -k effe296100000018 > killed 0 states > > root@freebsd:/ # pfctl -ss -vvv | tail -5 > all tcp 10.255.4.134:60684 -> 10.2.3.10:443 ESTABLISHED:ESTABLISHED > [1005467278 + 256] wscale 7 [2245470126 + 1117184] wscale 9 > age 60966:41:04, expires in 280894:34:40, 250677:343861 pkts, > 18984766:362137617 bytes, anchor 1308884992, rule 419430400 > id: effe296100000018 creatorid: e9c975c1 gateway: 0.0.0.0 > origif: ix0.167 > > is it possible to fix it? > > Regards > Same on current. From nobody Sun Aug 22 19:01:24 2021 X-Original-To: pf@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 39CD61778950 for ; Sun, 22 Aug 2021 19:01:27 +0000 (UTC) (envelope-from kp@FreeBSD.org) Received: from smtp.freebsd.org (smtp.freebsd.org [96.47.72.83]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "smtp.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Gt4Tz1CNdz3wJD; Sun, 22 Aug 2021 19:01:27 +0000 (UTC) (envelope-from kp@FreeBSD.org) Received: from venus.codepro.be (venus.codepro.be [5.9.86.228]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "mx1.codepro.be", Issuer "R3" (verified OK)) (Authenticated sender: kp) by smtp.freebsd.org (Postfix) with ESMTPSA id EC61046F3; Sun, 22 Aug 2021 19:01:26 +0000 (UTC) (envelope-from kp@FreeBSD.org) Received: by venus.codepro.be (Postfix, authenticated sender kp) id E1AB727917; Sun, 22 Aug 2021 21:01:24 +0200 (CEST) From: Kristof Provost To: Oleksandr Kryvulia Cc: pf@freebsd.org Subject: Re: pfctl -k id not working Date: Sun, 22 Aug 2021 21:01:24 +0200 X-Mailer: MailMate (1.14r5818) Message-ID: <903A7599-FFBD-4E7C-A4E9-2EA2F2C7B16C@FreeBSD.org> In-Reply-To: <437ea6f8-a93f-4650-1e94-c52110d328e7@shurik.kiev.ua> References: <437ea6f8-a93f-4650-1e94-c52110d328e7@shurik.kiev.ua> List-Id: Technical discussion and general questions about packet filter (pf) List-Archive: https://lists.freebsd.org/archives/freebsd-pf List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-pf@freebsd.org X-BeenThere: freebsd-pf@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable X-ThisMailContainsUnwantedMimeParts: N On 22 Aug 2021, at 20:58, Oleksandr Kryvulia wrote: > 20.08.21 22:01, =C3=96zkan KIRIK =D0=BF=D0=B8=D1=88=D0=B5=D1=82: >> Hi, >> >> I'm trying to kill a single state using state id. But even state exist= s, no >> (0) states are killed. >> >> I'm using FreeBSD stable/12 0f97f2a1857a (Jul 26) build. Outputs are b= elow: >> >> root@freebsd:/ # pfctl -ss -vvv | tail -5 >> all tcp 10.255.4.134:60684 -> 10.2.3.10:443 ESTABLISHED:ESTABLIS= HED >> [3857528462 + 256] wscale 7 [2278827950 + 1117184] wscale 9 >> age 1002336:42:40, expires in 252932:33:04, 250675:343858 pkts, >> 18984576:362136695 bytes, anchor 1308884992, rule 419430400 >> id: effe296100000018 creatorid: e9c975c1 gateway: 0.0.0.0 >> origif: ix0.167 >> >> root@freebsd:/ # pfctl -k id -k effe296100000018 >> killed 0 states >> >> root@freebsd:/ # pfctl -ss -vvv | tail -5 >> all tcp 10.255.4.134:60684 -> 10.2.3.10:443 ESTABLISHED:ESTABLIS= HED >> [1005467278 + 256] wscale 7 [2245470126 + 1117184] wscale 9 >> age 60966:41:04, expires in 280894:34:40, 250677:343861 pkts, >> 18984766:362137617 bytes, anchor 1308884992, rule 419430400 >> id: effe296100000018 creatorid: e9c975c1 gateway: 0.0.0.0 >> origif: ix0.167 >> >> is it possible to fix it? >> >> Regards >> > > Same on current. Thanks for the confirmation. It=E2=80=99s very likely fallout from the nv= list changes I did in that area recently. It=E2=80=99s on my list for Monday. It=E2=80=99s likely to be fairly easy= to fix. Best regards, Kristof From nobody Sun Aug 22 21:00:06 2021 X-Original-To: pf@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 903C01784691 for ; Sun, 22 Aug 2021 21:00:07 +0000 (UTC) (envelope-from bugzilla-noreply@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Gt76v1VbTz3G8C for ; Sun, 22 Aug 2021 21:00:07 +0000 (UTC) (envelope-from bugzilla-noreply@FreeBSD.org) Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2610:1c1:1:606c::50:1d]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id D861327659 for ; Sun, 22 Aug 2021 21:00:06 +0000 (UTC) (envelope-from bugzilla-noreply@FreeBSD.org) Received: from kenobi.freebsd.org ([127.0.1.5]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id 17ML06OP052927 for ; Sun, 22 Aug 2021 21:00:06 GMT (envelope-from bugzilla-noreply@FreeBSD.org) Received: (from bugzilla@localhost) by kenobi.freebsd.org (8.15.2/8.15.2/Submit) id 17ML06XJ052926 for pf@FreeBSD.org; Sun, 22 Aug 2021 21:00:06 GMT (envelope-from bugzilla-noreply@FreeBSD.org) Message-Id: <202108222100.17ML06XJ052926@kenobi.freebsd.org> X-Authentication-Warning: kenobi.freebsd.org: bugzilla set sender to bugzilla-noreply@FreeBSD.org using -f From: bugzilla-noreply@FreeBSD.org To: pf@FreeBSD.org Subject: Problem reports for pf@FreeBSD.org that need special attention Date: Sun, 22 Aug 2021 21:00:06 +0000 List-Id: Technical discussion and general questions about packet filter (pf) List-Archive: https://lists.freebsd.org/archives/freebsd-pf List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-pf@freebsd.org X-BeenThere: freebsd-pf@freebsd.org MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="16296660064.Ca4ecB1.52715" Content-Transfer-Encoding: 7bit X-ThisMailContainsUnwantedMimeParts: Y --16296660064.Ca4ecB1.52715 Date: Sun, 22 Aug 2021 21:00:06 +0000 MIME-Version: 1.0 Content-Type: text/plain; charset="UTF-8" To view an individual PR, use: https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=(Bug Id). The following is a listing of current problems submitted by FreeBSD users, which need special attention. These represent problem reports covering all versions including experimental development code and obsolete releases. Status | Bug Id | Description ------------+-----------+--------------------------------------------------- Open | 237973 | pf: implement egress keyword to simplify rules ac 1 problems total for which you should take action. --16296660064.Ca4ecB1.52715--