From owner-freebsd-pf@FreeBSD.ORG Thu May 8 14:39:36 2008 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 8E5051065721 for ; Thu, 8 May 2008 14:39:36 +0000 (UTC) (envelope-from viaprog@gmail.com) Received: from rv-out-0506.google.com (rv-out-0506.google.com [209.85.198.224]) by mx1.freebsd.org (Postfix) with ESMTP id 652708FC14 for ; Thu, 8 May 2008 14:39:36 +0000 (UTC) (envelope-from viaprog@gmail.com) Received: by rv-out-0506.google.com with SMTP id b25so1339481rvf.43 for ; Thu, 08 May 2008 07:39:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:message-id:date:from:to:subject:mime-version:content-type:content-transfer-encoding:content-disposition; bh=D6Di//LGyWrw0wsDoBqQu1MAMK25dt6DB7p06VILVSo=; b=JYACz+G9IX8bx/djI+WrlcJOXYRxgkH4sjfjjMKRZi+Y/wm3voSDb31eOU0pK3V/Ggnv0q8OTFWMmoOOs+QW/+RWnd3coRdrIl3ChMPsIWvwtCC+TmZbFiFTklPxD3kLdPXWuC2b6i5B4UIjSdlxlKGnzKMFNY+SjLYn+3ncHHY= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:date:from:to:subject:mime-version:content-type:content-transfer-encoding:content-disposition; b=H0rwmsR2UwJ0mJGZBWTNUmXEPnkEjuL9UDqxV/UKS276zjb922eR7TB+bJgcZa8U9Vo0QCQublK83O684hq0dpR4/9Ta6R9xIn64U/DElDO87ccAIsRSsXDEbApdlzrnnMSTyR9ZkSA22IZc2KL57D+fpXkJtt1QFah/COuK180= Received: by 10.141.71.14 with SMTP id y14mr1533933rvk.253.1210255853152; Thu, 08 May 2008 07:10:53 -0700 (PDT) Received: by 10.140.187.7 with HTTP; Thu, 8 May 2008 07:10:52 -0700 (PDT) Message-ID: Date: Thu, 8 May 2008 18:10:53 +0400 From: "Igor A. Valcov" To: freebsd-pf@freebsd.org, freebsd-hackers@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Content-Disposition: inline Cc: Subject: do not work nested unnamed anchor X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 08 May 2008 14:39:36 -0000 Hello. For example: ==== pf.conf ==== ext_if="xl0" ip_world="nn.nn.nn.nn" # Filter rules block log all anchor in on $ext_if { pass quick proto tcp to $ip_world port 22 keep state # SSH pass quick proto tcp to $ip_world port 25 keep state # SMTP pass quick proto tcp to $ip_world port 110 keep state # POP3 anchor { pass quick proto tcp to $ip_world port 995 keep state # POP3S } } ============ nmap results: PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 4.5p1 (FreeBSD 20061110; protocol 2.0) 25/tcp open smtp? 110/tcp open pop3 Openwall popa3d I can not understand what the problem... FreeBSD-7.0-RELEASE-p1 i386 -- Igor A. Valcov