From owner-freebsd-pf@FreeBSD.ORG Fri Sep 21 17:43:24 2007 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 8FD2F16A420 for ; Fri, 21 Sep 2007 17:43:24 +0000 (UTC) (envelope-from odhiambo@gmail.com) Received: from rv-out-0910.google.com (rv-out-0910.google.com [209.85.198.186]) by mx1.freebsd.org (Postfix) with ESMTP id 60B4213C480 for ; Fri, 21 Sep 2007 17:43:24 +0000 (UTC) (envelope-from odhiambo@gmail.com) Received: by rv-out-0910.google.com with SMTP id l15so755324rvb for ; Fri, 21 Sep 2007 10:43:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:to:subject:mime-version:content-type:content-transfer-encoding:content-disposition; bh=fdOHHpzjAxQ1HxhY3QU/NTmftih8WJ3gTQNlHzyBFIQ=; b=ZyTpXyj6+U/cHGf9Jc4zffEke6BMPbopSeMMsj/0EezaWQYJ19vljXLVEQn0CyGZKoUsrwhLTNb/SGoS4mz74TPQ5RdKre74gVKphNI4XureGQ3oY2YaFFLHfCry6x5b+RSjoZ1/XRiaFZF6V/C7pZXg+zZn6UKJHj03UmIMWrg= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:to:subject:mime-version:content-type:content-transfer-encoding:content-disposition; b=FRQCKpveA9O3TWJ1sh2yGdBxHQITLPy0meQicnda9Ad2VV10z9LjC0u4W4Mj5GySLTM96Fh9EjSPeHT20Q+ggZ7kPpyV53ykcuHjEeRILoEgaFqwjm/5d15h19wdU2WhwOwhP+71TCO6a4OgkI0qT5cMEqakquh6/+UAFd5n/9U= Received: by 10.115.111.1 with SMTP id o1mr150940wam.1190396221583; Fri, 21 Sep 2007 10:37:01 -0700 (PDT) Received: by 10.115.106.13 with HTTP; Fri, 21 Sep 2007 10:37:01 -0700 (PDT) Message-ID: <991123400709211037w7df6500ai4d01466823db5d4c@mail.gmail.com> Date: Fri, 21 Sep 2007 20:37:01 +0300 From: "Washington Odhiambo" To: freebsd-pf@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Content-Disposition: inline Subject: Weird Problem with NAT - more details X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 21 Sep 2007 17:43:24 -0000 Here is what tcpdump shows: spamfilter# tcpdump -vv -s 200 -i em0 src host 62.8.64.102 tcpdump: listening on em0, link-type EN10MB (Ethernet), capture size 200 bytes 20:29:37.401847 IP (tos 0x10, ttl 58, id 10542, offset 0, flags [DF], proto: TCP (6), length: 58) gw.57736 > 212.22.160.35.smtp: P, cksum 0xb82c (correct), 3160106269:3160106275(6) ack 3361902259 win 33072 20:29:37.406392 IP (tos 0x10, ttl 58, id 10544, offset 0, flags [DF], proto: TCP (6), length: 52) gw.57736 > 212.22.160.35.smtp: ., cksum 0x86ea (correct), 6:6(0) ack 48 win 33072 20:29:37.406395 IP (tos 0x10, ttl 58, id 10545, offset 0, flags [DF], proto: TCP (6), length: 52) gw.57736 > 212.22.160.35.smtp: F, cksum 0x86e9 (correct), 6:6(0) ack 48 win 33072 20:29:38.045803 IP (tos 0x10, ttl 58, id 10554, offset 0, flags [DF], proto: TCP (6), length: 64) gw.64570 > 212.22.160.35.smtp: S, cksum 0xce1f (correct), 4219889009:4219889009(0) win 65535 20:29:38.050332 IP (tos 0x10, ttl 58, id 10556, offset 0, flags [DF], proto: TCP (6), length: 52) gw.64570 > 212.22.160.35.smtp: ., cksum 0x821e (correct), 4219889010:4219889010(0) ack 697685838 win 33072 20:29:38.151100 IP (tos 0x10, ttl 58, id 10559, offset 0, flags [DF], proto: TCP (6), length: 52) gw.64570 > 212.22.160.35.smtp: ., cksum 0x81bd (correct), 0:0(0) ack 76 win 33072 20:29:56.811400 IP (tos 0x10, ttl 58, id 10571, offset 0, flags [DF], proto: TCP (6), length: 58) gw.64570 > 212.22.160.35.smtp: P, cksum 0x8b2c (correct), 0:6(6) ack 76 win 33072 20:29:56.831815 IP (tos 0x10, ttl 58, id 10573, offset 0, flags [DF], proto: TCP (6), length: 52) gw.64570 > 212.22.160.35.smtp: ., cksum 0x644b (correct), 6:6(0) ack 123 win 33072 20:29:56.831818 IP (tos 0x10, ttl 58, id 10574, offset 0, flags [DF], proto: TCP (6), length: 52) gw.64570 > 212.22.160.35.smtp: F, cksum 0x644a (correct), 6:6(0) ack 123 win 33072 20:29:59.111452 IP (tos 0x10, ttl 58, id 10593, offset 0, flags [DF], proto: TCP (6), length: 64) gw.50020 > 212.22.160.35.pop3: S, cksum 0x0171 (correct), 552613063:552613063(0) win 65535 20:30:02.086455 IP (tos 0x10, ttl 58, id 10597, offset 0, flags [DF], proto: TCP (6), length: 64) gw.50020 > 212.22.160.35.pop3: S, cksum 0xff18 (correct), 552613063:552613063(0) win 65535 20:30:05.290926 IP (tos 0x10, ttl 58, id 10598, offset 0, flags [DF], proto: TCP (6), length: 64) gw.50020 > 212.22.160.35.pop3: S, cksum 0xfc98 (correct), 552613063:552613063(0) win 65535 20:30:08.486187 IP (tos 0x10, ttl 58, id 10599, offset 0, flags [DF], proto: TCP (6), length: 48) gw.50020 > 212.22.160.35.pop3: S, cksum 0x7834 (correct), 552613063:552613063(0) win 65535 20:30:11.700449 IP (tos 0x10, ttl 58, id 10600, offset 0, flags [DF], proto: TCP (6), length: 48) gw.50020 > 212.22.160.35.pop3: S, cksum 0x7834 (correct), 552613063:552613063(0) win 65535 ^C 14 packets captured 111 packets received by filter 0 packets dropped by kernel spamfilter# tcpdump -vv -s 200 -i em0 src host 62.8.64.102 tcpdump: listening on em0, link-type EN10MB (Ethernet), capture size 200 bytes 20:30:44.177381 IP (tos 0x10, ttl 58, id 10640, offset 0, flags [DF], proto: TCP (6), length: 64) gw.53026 > 212.22.160.35.3000: S, cksum 0x85c1 (correct), 4224097118:4224097118(0) win 65535 20:30:47.172263 IP (tos 0x10, ttl 58, id 10644, offset 0, flags [DF], proto: TCP (6), length: 64) gw.53026 > 212.22.160.35.3000: S, cksum 0x8369 (correct), 4224097118:4224097118(0) win 65535 20:30:50.396927 IP (tos 0x10, ttl 58, id 10645, offset 0, flags [DF], proto: TCP (6), length: 64) gw.53026 > 212.22.160.35.3000: S, cksum 0x80e9 (correct), 4224097118:4224097118(0) win 65535