From owner-freebsd-questions@FreeBSD.ORG Thu Jun 9 18:15:53 2005 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 4E6C916A428 for ; Thu, 9 Jun 2005 18:15:53 +0000 (GMT) (envelope-from dannyman@toldme.com) Received: from shiva.nextrials.com (shiva.nextrials.com [64.81.74.145]) by mx1.FreeBSD.org (Postfix) with ESMTP id 2A48543D1F for ; Thu, 9 Jun 2005 18:15:53 +0000 (GMT) (envelope-from dannyman@toldme.com) Received: from [192.168.1.102] (mito.sr.nextrials.com [192.168.1.102]) by shiva.nextrials.com (Postfix) with ESMTP id B69293C2873; Thu, 9 Jun 2005 11:15:52 -0700 (PDT) Message-ID: <42A88757.8070601@toldme.com> Date: Thu, 09 Jun 2005 11:15:51 -0700 From: Danny Howard User-Agent: Mozilla Thunderbird 1.0.2 (X11/20050607) X-Accept-Language: en-us, en MIME-Version: 1.0 To: "James Bowman Sineath, III" References: <004301c56c8a$686010a0$0463a8c0@GARUDA> In-Reply-To: <004301c56c8a$686010a0$0463a8c0@GARUDA> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Cc: FreeBSD Questions Subject: Re: ipf blocking pass rule X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 09 Jun 2005 18:15:53 -0000 James Bowman Sineath, III wrote: James, You should send messages to the list directly. When you start your question by hitting "reply" to a question about shell accounts, your message will be lumped under there in a lot of mail clients, and is less likely to be see. > I have the following rule in my ipf.rules: > > pass in log first quick on xl0 proto tcp from any to any port = 25 > keep state > > for some reason it will pass the first connection but block the next. > A log is below. Any ideas on why this is happening would be much > appreciated. I'm no IPF expert, but I'd wonder if "pass in log FIRST quick" is doing exactly what you describe correctly ... -d -- http://dannyman.toldme.com/