From owner-freebsd-pf@FreeBSD.ORG Mon Sep 22 11:53:10 2008 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 7C655106567B for ; Mon, 22 Sep 2008 11:53:10 +0000 (UTC) (envelope-from leslie@eskk.nu) Received: from hawk.thalamus.net (hawk.thalamus.net [212.31.160.3]) by mx1.freebsd.org (Postfix) with ESMTP id 3F2BF8FC08 for ; Mon, 22 Sep 2008 11:53:09 +0000 (UTC) (envelope-from leslie@eskk.nu) Received: from localhost (localhost.thalamus.net [127.0.0.1]) by hawk.thalamus.net (Postfix) with ESMTP id D60CF216C12 for ; Mon, 22 Sep 2008 13:53:05 +0200 (CEST) X-Virus-Scanned: by amavisd-new at thalamus.net X-Spam-Flag: NO X-Spam-Score: 2.379 X-Spam-Level: ** X-Spam-Status: No, score=2.379 tagged_above=-999 required=4.2 tests=[AWL=-0.790, HELO_LH_HOME=3.169] Received: from hawk.thalamus.net ([127.0.0.1]) by localhost (hawk.thalamus.net [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5Kdc1VgMDpdn for ; Mon, 22 Sep 2008 13:52:59 +0200 (CEST) Received: from bljbsd01.homenet.home (c-195-216-040-164.static.bjare.net [195.216.40.164]) by hawk.thalamus.net (Postfix) with ESMTP id 4E67E216C6B for ; Mon, 22 Sep 2008 13:52:59 +0200 (CEST) Message-ID: <48D7871E.1040902@eskk.nu> Date: Mon, 22 Sep 2008 13:53:02 +0200 From: Leslie Jensen User-Agent: Thunderbird 2.0.0.16 (X11/20080917) MIME-Version: 1.0 To: freebsd-pf@freebsd.org Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Subject: IMAP server talks back PF blocks X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 22 Sep 2008 11:53:10 -0000 When doing tcpdump -n -e -ttt -i pflog0 I frequently see packets blocked that looks like this 458660 rule 0/0(match): block in on em0: xxx.yyy.zzz.qqq.993 > qqq.zzz.yyy.xxx.59930: tcp 8 [bad hdr length 12 - too short, < 20] It's the IMAP server I'm using that tries to talk back. Is this something I should try to let through? /Leslie