Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 8 Nov 2013 09:08:25 -0500
From:      Jason Hellenthal <jhellenthal@dataix.net>
To:        claudiu vasadi <claudiu.vasadi@gmail.com>
Cc:        "freebsd-pf@freebsd.org" <freebsd-pf@freebsd.org>
Subject:   Re: FreeBSD 9.1-STABLE - pf rule being ignored
Message-ID:  <6BF6F30B-F937-4C59-819A-770489B90343@dataix.net>
In-Reply-To: <C55476A9-F352-4615-9DFB-8705D583DCC1@dataix.net>
References:  <CAM-i3ihX43UxmrM-ThOP=nK2qr=jMpzab-zB7o_x--C2eDWUKg@mail.gmail.com> <C55476A9-F352-4615-9DFB-8705D583DCC1@dataix.net>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Should say too  . . . don't forget to either skip on lo0 or pass on lo0

> On Nov 8, 2013, at 9:05, Jason Hellenthal <jhellenthal@dataix.net> wrote:
> 
> Curious if your line breaks are correct ? Your block and pass rule appear to be on the same line.
> 
> This should do it . . . 
> 
> block in all
> block return in quick from !$internal_ip to $external_ip
> pass out all keep state
> 
> 
> But if you already have a block all rul there is no need for the second as your already blocking all traffic so I might suggest this not mowing your topology.
> 
> I also would not suggest "return" for non internal traffic except for specific targeted services that it might affect.
> . . . 
> :BEGIN
> 
> spoof on lo0
> spoof on $ext_if
> 
> block all
> pass out quick from $me
> pass in quick from $int to $me
> 
> :END 
> 
> And that should accomplish what you are trying to do IIUC.
> 
> You can use pftop to verify packets on hit rules.
> 
>> On Nov 8, 2013, at 8:41, claudiu vasadi <claudiu.vasadi@gmail.com> wrote:
>> 
>> Hi all,
>> 
>> I have a 9.1-STABLE r251615 acting as a firewall.
>> 
>> The rules:
>> block in all pass out all keep state [...] block return from !$internal_ip
>> to $external_ip
>> 
>> 
>> 
>> What I want is to block all the network except $internal to from accessing
>> $external_ip. For some reason, the above rule simply does not work.
>> However, the below does work and block everyone except $internal_ip:
>> 
>> block return from $internal_net/24 to $external_ip pass from $internal_ip
>> to $external_ip
>> 
>> 
>> Why is this? I remember reading the docs for OpenBSD 4.5 and I guess it
>> should work like in the first example.
>> 
>> PS: Yes, I can see the rule with pfctl -sr and it does translate properly.
>> 
>> -- 
>> Best regards,
>> Claudiu Vasadi
>> _______________________________________________
>> freebsd-pf@freebsd.org mailing list
>> http://lists.freebsd.org/mailman/listinfo/freebsd-pf
>> To unsubscribe, send any mail to "freebsd-pf-unsubscribe@freebsd.org"

[-- Attachment #2 --]
0	*H
010	+0	*H
90000
	*H
010	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 1 Primary Intermediate Client CA0
130518085048Z
140519220947Z0H10Ujhellenthal@dataix.net1%0#	*H
	jhellenthal@dataix.net0"0
	*H
0
'`TmfkܨJ5u+c'Upb`zv)&ȸXZ*VN6JvLoVoh}g
pQDŽKf/tZA˳("4Ԅ˻'d2h|IBl'^v^;'e8S99ۿVm|k8_UQtC"5l!kjZ]އQGn\BŽh!FTsD%pV^Eӑd¨x͸"9
г"f00	U00U0U%0++0UڔfmVʢ$䟓0U#0Sr풜\|~5NԸQ0!U0jhellenthal@dataix.net0LU C0?0;+70*0.+"http://www.startssl.com/policy.pdf0+00' StartCom Certification Authority0This certificate was issued according to the Class 1 Validation requirements of the StartCom CA policy, reliance only for the intended purpose in compliance of the relying party obligations.06U/0-0+)'%http://crl.startssl.com/crtu1-crl.crl0+009+0-http://ocsp.startssl.com/sub/class1/client/ca0B+06http://aia.startssl.com/certs/sub.class1.client.ca.crt0#U0http://www.startssl.com/0
	*H
{0Ӹ,52W{Ey8b[{7_+P"n["-,@ŽpJ-W$ݍjWA-6z(	RdIZ.KzXє[K6}{s+v.Qh0PͅKhTw0I73lz*Kv4Kkگ63;p1:ױ@)]ok>:W%XwC1þL/o8~#oP0400
	*H
0}10	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1)0'U StartCom Certification Authority0
071024210155Z
171024210155Z010	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 1 Primary Intermediate Client CA0"0
	*H
0
	-).2AUGo#G
B|NDRpM-B=o-we5JQpa>O.#._<V
[~**pz~3WG.ᘟMlr[<Ce6fqO"uxfWN#uicgkv$Lb%y`_{`xK'GN00U00U0USr풜\|~5NԸQ0U#0N@[i04hCA0f+Z0X0'+0http://ocsp.startssl.com/ca0-+0!http://www.startssl.com/sfsca.crt0[UT0R0'%#!http://www.startssl.com/sfsca.crl0'%#!http://crl.startssl.com/sfsca.crl0U y0w0u+70f0.+"http://www.startssl.com/policy.pdf04+(http://www.startssl.com/intermediate.pdf0
	*H

}x,\c^#wMq}>UK/^yX֏y	frMIŲB61ymQ󸟆ҨݬZ0&;@#13qۑ&	̢o	6r_;GO>*I(	74XS1r3)!LJy6Kotˆ#
_wSr
;B
ADp(fs䰷6%.W0J3:bC<8t X1<Cn=t==wST~\wkBf|15zUP)(IjVB!OfI=bb\4-*em/нSJm7N[]'@ڽD9Kr>R7/|o^I@ټ'Pa$ z9a'L)(
I}vcH]۸D*W}
m>Q|C.(,lQ000
	*H
0}10	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1)0'U StartCom Certification Authority0
060917194636Z
360917194636Z0}10	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1)0'U StartCom Certification Authority0"0
	*H
0
	lF|x{3rb6 "$^wC
d̎68#nm<r=3+/AYg}
tyL7z9RYFC҅qub4,4ǖR=3M;JK&/r5w<]&6v\t%x-0-ryF*I
cSb:̵fkt+v>mDsb;ľSV%lQ	ʿvmۿ=fVH:KߧXP8u[ClMp[)eݪ]̯1ҍ{n'fHnB?!>{
pclT\%zɢɋ,~^MXn
2n6IHi–Mi
y"H{ipz7
vOW`g:ԋr"Ɵƶ\R<*s
`z/ۣn&0݉W=+ŷv+*r3]	K߻tRKR0N0U00U0UN@[i04hCA0dU]0[0,*(&http://cert.startcom.org/sfsca-crl.crl0+)'%http://crl.startcom.org/sfsca-crl.crl0]U T0P0L+70;0/+#http://cert.startcom.org/policy.pdf05+)http://cert.startcom.org/intermediate.pdf0+00' Start Commercial (StartCom) Ltd.0Limited Liability, read the section *Legal Limitations* of the StartCom Certification Authority Policy available at http://cert.startcom.org/policy.pdf0	`HB08	`HB
+)StartCom Free SSL Certification Authority0
	*H
lf4Ѕ^}
N8^ߦ%K2;=D	[I)f%	<6+Kh9f=&9Q{~ZWpi^X
ߌE8
^Wbz)n(DÐ8<CMdE(\s{諱.\dns1:}Q;Mf{<ӚePu/CiyCFrd6%8w~kjDKx,KD4R'
]xS2݀fuٵh(a.8gd./pǖ|eCTݥ9`4ɖp,H{~k";*RKU"4N&",uJ}׸d6/#	;sIjWxřCcMw-eriG	V$yX.	~m>J9+u	U77Cb VKel$$4"}?eQ
0j
r^1o0k0010	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 1 Primary Intermediate Client CA0	+0	*H
	1	*H
0	*H
	1
131108140827Z0#	*H
	1pA|x"b0	+710010	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 1 Primary Intermediate Client CA0*H
	1010	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 1 Primary Intermediate Client CA0
	*H
?Sb%*M)$Th3(Ymk1e^6-&YI'*9b$ۼ kixMm.:LxcaRBOv tWѴr=>o?ן5qR+D;GD#$w*q,7Omu +~֓:Z*䨥G6W{KA	Kڨc

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?6BF6F30B-F937-4C59-819A-770489B90343>