From owner-freebsd-questions@FreeBSD.ORG Wed Oct 15 21:23:01 2008 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id E5FD51065699 for ; Wed, 15 Oct 2008 21:23:01 +0000 (UTC) (envelope-from clarkp@mtmary.edu) Received: from fear.mtmary.edu (rrcs-74-62-87-82.west.biz.rr.com [74.62.87.82]) by mx1.freebsd.org (Postfix) with ESMTP id BFA008FC0C for ; Wed, 15 Oct 2008 21:23:01 +0000 (UTC) (envelope-from clarkp@mtmary.edu) Received: from [127.0.0.1] (war.mtmary.edu [172.16.0.200]) by fear.mtmary.edu (Postfix) with ESMTP id 80D9F4F6A3A; Wed, 15 Oct 2008 16:23:00 -0500 (CDT) Message-ID: <48F65F33.9060200@mtmary.edu> Date: Wed, 15 Oct 2008 16:22:59 -0500 From: Peter Clark User-Agent: Thunderbird 2.0.0.17 (Windows/20080914) MIME-Version: 1.0 To: Yury Michurin References: <48F621C2.8080405@mtmary.edu> <692c9a9f0810151405t3e573cfs3fd4d2a801110c89@mail.gmail.com> In-Reply-To: <692c9a9f0810151405t3e573cfs3fd4d2a801110c89@mail.gmail.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Cc: FreeBSD Questions Subject: Re: PF syntax error X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 15 Oct 2008 21:23:02 -0000 Yury Michurin wrote: > Hello, > I have in my pf.conf: > pass in proto tcp from ! to any port www flags S/SA synproxy > state (max-src-conn 20, max-src-conn-rate 30/60, overload > flush global) > > and it seems to work just fine... > > Regards, > Yury. > > On Wed, Oct 15, 2008 at 7:00 PM, Peter Clark > wrote: > > Hello, > > I am not sure if I should be here or over at a pf specific list but > here is my problem. > > I am trying my hand at pf on a 7.0-p5 RELEASE box and one rule is > giving me problems. > > pass in quick on $ext_if proto tcp from any to any port 22 flags S/SA \ > (max-src-conn 15, max-src-conn-rate 5/3, overload > flush global) > > Actually the "pass in" line does not generate the error. The next > line does. > > /etc/pf.conf:71: syntax error > If I remove the line the error goes away (obviously). I have tried > using the exact line from the FreeBSD pf.conf man page: > > (max-src-conn-rate 100/10, overload flush global) > > (I changed to )and that generates the same > error. I tried just using: > (max-src-conn-rate 100/10) > > but that too gives me a syntax error. > > Any help is appreciated. > > Peter Clark > > _______________________________________________ > freebsd-questions@freebsd.org > mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-questions > To unsubscribe, send any mail to > "freebsd-questions-unsubscribe@freebsd.org > " > > It is because I do not have a "keep state" directive in mine. I took it out because the pf 4.1 default is "flags S/SA keep state". Yours works because you have the synproxy state directive. Thanks, Peter Clark