From owner-freebsd-pf@freebsd.org Mon Nov 20 11:09:33 2017 Return-Path: Delivered-To: freebsd-pf@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 84E47DE8247 for ; Mon, 20 Nov 2017 11:09:33 +0000 (UTC) (envelope-from bounces+4591149-c82b-freebsd-pf=freebsd.org@sendgrid.net) Received: from o7.delivery.customeriomail.com (o7.delivery.customeriomail.com [167.89.32.154]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 45C9B79B51 for ; Mon, 20 Nov 2017 11:09:32 +0000 (UTC) (envelope-from bounces+4591149-c82b-freebsd-pf=freebsd.org@sendgrid.net) DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=remote.com; h=content-type:from:mime-version:subject:to; s=smtpapi; bh=bvm5dlshHPSTqBAHtTAWOsmS0qc=; b=Jhj/Gsy7kVC4WQTXbp2jJgcRSpwP5 z3pRdrNtW0o4vpVWxNFQL83diEtKz0MWRDduNO2fkJpfjPWgB45BvfNekjkt2O/S 1TxJvSQdjU4d2cTJE/0sValFXc1dDT2DIGSGhpxzpzmR/X/dnM6e6oJsPOInZ55t gJvNshe6CHobe4= Received: by filter1210p1mdw1.sendgrid.net with SMTP id filter1210p1mdw1-18994-5A12B7E6-5 2017-11-20 11:09:26.061637771 +0000 UTC Received: from localhost (87.232.154.104.bc.googleusercontent.com [104.154.232.87]) by ismtpd0001p1iad1.sendgrid.net (SG) with ESMTP id Tnr4id_lSGmWEduSRPArUQ for ; Mon, 20 Nov 2017 11:09:25.962 +0000 (UTC) Date: Mon, 20 Nov 2017 11:09:26 +0000 (UTC) From: "Istvan Szukacs" Message-Id: Mime-Version: 1.0 Subject: Join me on Remote.com To: X-Mailer: Customer.io (ZOTaAwABX9keU4wgCujKevjvCBBZ; +https://whatis.customeriomail.com) X-Report-Abuse-To: badactor@customer.io X-SG-EID: Vb+Anvs0EfIvXbjCHlZrgZXQJbLnUdd6UfS6gElhdS2FAY8xSnBqB1xUpcuaDLCYyWkyAx4XinM/hL hDhfI00MC2+xPC7GwstibG6bscosftq/5M6WC2psn9r0fKU4T7bOvy+UoJHmRBfc63GsTNUfSUKK83 P1VnEwmaO4ggoOP6YguytguY0bEfIx6ciKN9PAkJGPGSROsED7BLDCoa1U8ly2Waj/3BSD7tl4EfYu c= X-SG-ID: YDTqBOjidbCUo/ar1oAtZmb+xY/SddQ88JdQsa2vytmZWQv/GTJ54wZAyQ1vsMC5knfwxGdDlq+w93 ++Scj0XA== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Content-Filtered-By: Mailman/MimeDel 2.1.25 X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.25 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 20 Nov 2017 11:09:33 -0000 Image Istvan Szukacs CTO / DATA --------------------- Istvan invited you to connect on Remote.com --------------------- Join over 2 million people in the fastest growing community for remote and = freelance work. Remote.com connects people all over the world with remote a= nd freelance jobs. Join the evolution. Accept Invitation ( https://remote.com/?inviter=3Distvanszukacs ) Image 1860 El Camino Real Suite 401, Burlingame CA 94010 Update email preferences ( https://remote.com/settings/notifications ) or u= nsubscribe ( https://remote.com/unsubscribe?from=3Dinvite&token=3DVE9LRU4uV= jEvNWExMmI3OWNlYjk3OWQwMDA3ZGFlMDNlL2ZyZWVic2QtcGZAZnJlZWJzZC5vcmcvaW52aXRl= LzE1MTExNzYwOTI.QYeYrErsm9MkyiXbPTmntz-imsw )= From owner-freebsd-pf@freebsd.org Tue Nov 21 00:07:28 2017 Return-Path: Delivered-To: freebsd-pf@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id C5001DB80C4 for ; Tue, 21 Nov 2017 00:07:28 +0000 (UTC) (envelope-from dave@horsfall.org) Received: from viclamta12p.bpe.bigpond.com (viclamta12p.bpe.bigpond.com [203.38.21.76]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "", Issuer "Openwave Messaging Inc." (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 9622B7373F for ; Tue, 21 Nov 2017 00:07:24 +0000 (UTC) (envelope-from dave@horsfall.org) Received: from smtp.telstra.com ([10.10.26.4]) by viclafep09p-svc.bpe.nexus.telstra.com.au with ESMTP id <20171120221820.HEEJ25268.viclafep09p-svc.bpe.nexus.telstra.com.au@smtp.telstra.com> for ; Tue, 21 Nov 2017 09:18:20 +1100 X-RG-Spam: Unknown X-Junkmail-Premium-Raw: score=8/83, refid=2.7.2:2017.11.20.214516:17:8.129, ip=, rules=__HAS_FROM, __TO_MALFORMED_2, __TO_NAME, __TO_NAME_DIFF_FROM_ACC, __BOUNCE_CHALLENGE_SUBJ, __BOUNCE_NDR_SUBJ_EXEMPT, __IN_REP_TO, __HAS_MSGID, __SANE_MSGID, __REFERENCES, __USER_AGENT, __MIME_VERSION, __CT, __CTYPE_HAS_BOUNDARY, __CTYPE_MULTIPART, __CTYPE_MULTIPART_MIXED, __MIME_TEXT_P2, __SUBJ_ALPHA_NEGATE, __NO_HTML_TAG_RAW, BODYTEXTP_SIZE_3000_LESS, BODY_SIZE_800_899, __MIME_TEXT_P1, __MIME_TEXT_ONLY, HTML_00_01, HTML_00_10, BODY_SIZE_5000_LESS, IN_REP_TO, MSG_THREAD, __TO_REAL_NAMES, LEGITIMATE_SIGNS, NO_URI_FOUND, NO_CTA_URI_FOUND, BODY_SIZE_1000_LESS, BODY_SIZE_2000_LESS, SMALL_BODY, __MIME_TEXT_P, REFERENCES, NO_URI_HTTPS, BODY_SIZE_7000_LESS, MIME_TEXT_ONLY_MP_MIXED X-RG-VS-Verdict: clean X-RazorGate-Vade: gggruggvucftvghtrhhoucdtuddrfeelgedrkeelgdduudefucetufdoteggodetrfdotffvucfrrhhofhhilhgvmecuuffpveftpgfvgffnuffvtfetnecuuegrihhlohhuthemuceftddtnecusecvtfgvtghiphhivghnthhsucdlqddutddtmdenucfjughrpeffhffvufgjkfhffgggtgesmhdttdertderjeenucfhrhhomhepffgrvhgvucfjohhrshhfrghllhcuoegurghvvgeshhhorhhsfhgrlhhlrdhorhhgqeenucfkphepuddutddrudeguddrudelfedrvdeffeenucfrrghrrghmpehhvghloheprghnvghurhhinhdrhhhorhhsfhgrlhhlrdhorhhgpdhinhgvthepuddutddrudeguddrudelfedrvdeffedpmhgrihhlfhhrohhmpeeouggrvhgvsehhohhrshhfrghllhdr Received: from aneurin.horsfall.org (110.141.193.233) by smtp.telstra.com (9.0.019.22-1) id 5A0DD2DB008B9A2B for freebsd-pf@freebsd.org; Tue, 21 Nov 2017 09:18:19 +1100 Received: from aneurin.horsfall.org (localhost [127.0.0.1]) by aneurin.horsfall.org (8.15.2/8.15.2) with ESMTP id vAKMIJOX018050 for ; Tue, 21 Nov 2017 09:18:19 +1100 (EST) (envelope-from dave@horsfall.org) Received: from localhost (dave@localhost) by aneurin.horsfall.org (8.15.2/8.15.2/Submit) with ESMTP id vAKMIIck018047 for ; Tue, 21 Nov 2017 09:18:19 +1100 (EST) (envelope-from dave@horsfall.org) X-Authentication-Warning: aneurin.horsfall.org: dave owned process doing -bs Date: Tue, 21 Nov 2017 09:18:18 +1100 (EST) From: Dave Horsfall To: FreeBSD PF List Subject: Re: Why is PF rejecting these connections? In-Reply-To: <80FABA34-F562-4158-B083-E1488345F249@sigsegv.be> Message-ID: References: <80FABA34-F562-4158-B083-E1488345F249@sigsegv.be> User-Agent: Alpine 2.21 (BSF 202 2017-01-01) X-GPG-Public-Key: http://www.horsfall.org/gpgkey.pub X-GPG-Fingerprint: 05B4 FFBC 0218 B438 66E0 587B EF46 7357 EF5E F58B X-Home-Page: http://www.horsfall.org/ X-Witty-Saying: "chmod 666 the_mode_of_the_beast" MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 8BIT X-Content-Filtered-By: Mailman/MimeDel 2.1.25 X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.25 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 21 Nov 2017 00:07:28 -0000 On Sat, 18 Nov 2017, Kristof Provost wrote: > Can you post a full pcap capture? It’s very hard to figure things out > from a text summary of a packet. Where and how were these logged? How do > you know they’re being dropped? Sigh... It was my mistake; I had utterly forgotten that I had logging enabled for the table (and some of them are damned persistent). Sorry for the noise; I'll just quietly slink off now and keep quiet for a while... -- Dave Horsfall DTM (VK2KFU) "Those who don't understand security will suffer." From owner-freebsd-pf@freebsd.org Wed Nov 22 13:25:42 2017 Return-Path: Delivered-To: freebsd-pf@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id EE304DEB76F for ; Wed, 22 Nov 2017 13:25:42 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2001:1900:2254:206a::16:76]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id DC5D87A2C9 for ; Wed, 22 Nov 2017 13:25:42 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from bugs.freebsd.org ([127.0.1.118]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id vAMDPgwE005904 for ; Wed, 22 Nov 2017 13:25:42 GMT (envelope-from bugzilla-noreply@freebsd.org) From: bugzilla-noreply@freebsd.org To: freebsd-pf@FreeBSD.org Subject: [Bug 213736] pf: hardcoded if_output skips ip[6]_output and pfil order Date: Wed, 22 Nov 2017 13:25:42 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: kern X-Bugzilla-Version: CURRENT X-Bugzilla-Keywords: X-Bugzilla-Severity: Affects Only Me X-Bugzilla-Who: franco@opnsense.org X-Bugzilla-Status: Closed X-Bugzilla-Resolution: Feedback Timeout X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: freebsd-pf@FreeBSD.org X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: bug_status resolution Message-ID: In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated MIME-Version: 1.0 X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.25 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 22 Nov 2017 13:25:43 -0000 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D213736 Franco Fichtner changed: What |Removed |Added ---------------------------------------------------------------------------- Status|New |Closed Resolution|--- |Feedback Timeout --=20 You are receiving this mail because: You are the assignee for the bug.=