From owner-freebsd-questions@FreeBSD.ORG Mon Oct 6 13:44:56 2008 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 0F0501065693 for ; Mon, 6 Oct 2008 13:44:56 +0000 (UTC) (envelope-from jamesoff@gmail.com) Received: from yx-out-2324.google.com (yx-out-2324.google.com [74.125.44.30]) by mx1.freebsd.org (Postfix) with ESMTP id B9E5A8FC1D for ; Mon, 6 Oct 2008 13:44:55 +0000 (UTC) (envelope-from jamesoff@gmail.com) Received: by yx-out-2324.google.com with SMTP id 8so443557yxb.13 for ; Mon, 06 Oct 2008 06:44:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:message-id:date:from:to :subject:cc:in-reply-to:mime-version:content-type :content-transfer-encoding:content-disposition:references; bh=FE1l/laMbHhY9cjC0J/P4JSok//LlqL/bPEnAr29aOI=; b=UgP6Ial4waXSYzZTTpzZ+QEHutWcqW4osCb1QIsRG0Ht49d039ABFsFG2NhHETwpAa /NVasVhZCHiw38JQt8gm5lWqYyynbQEhe2bGDZP9O2ipNRFDq5NKJgPxsTJ9wPggPtL4 3Ax6EDnfUNaeV9LinPjss44b7zjANUFwuMQPA= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:date:from:to:subject:cc:in-reply-to:mime-version :content-type:content-transfer-encoding:content-disposition :references; b=fIo0/t2oyiCiGnGdoViW/vIS8TBViDlOOVz5S1ktZdG/ldBXr23HrB3MjVd/UL9eRb Vb7qDjvUGwMWdUE5K2bzSNw1KbCUjkqWgCWXM5SVe6YmaSzH3Ywzo0rPxCERS2PHWX0P suPqkvnCCl7Xm1DxSmjgZ+BnWnd8aKl1nlkjM= Received: by 10.65.157.19 with SMTP id j19mr8465262qbo.68.1223300694578; Mon, 06 Oct 2008 06:44:54 -0700 (PDT) Received: by 10.65.132.10 with HTTP; Mon, 6 Oct 2008 06:44:54 -0700 (PDT) Message-ID: <720051dc0810060644n14495ee4k8f2942d16e634c78@mail.gmail.com> Date: Mon, 6 Oct 2008 14:44:54 +0100 From: "James Seward" To: "Jeremy Chadwick" In-Reply-To: <20081006115101.GA19442@icarus.home.lan> MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Content-Disposition: inline References: <200810051753.m95Hr3N5014872@mp.cs.niu.edu> <20081006003601.GA5733@icarus.home.lan> <48E9BBED.7090607@infracaninophile.co.uk> <20081006072611.GA13147@icarus.home.lan> <871vyuj6ul.fsf@kobe.laptop> <20081006115101.GA19442@icarus.home.lan> Cc: Giorgos Keramidas , Scott Bennett , freebsd-questions@freebsd.org Subject: Re: pf vs. RST attack question X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 06 Oct 2008 13:44:56 -0000 On Mon, Oct 6, 2008 at 12:51 PM, Jeremy Chadwick wrote: > I've never gotten a definite answer as to what happens if you use "flags > S/SA" on a rule that is for UDP, since UDP is a non-negotiated protocol. > That's why I split them up per protocol on RELENG_6 boxes. It intelligently ignores it: % pfctl -vn -f- pass out proto { tcp udp } all flags S/SA keep state Output: pass out proto tcp all flags S/SA keep state pass out proto udp all keep state /JMS