From owner-freebsd-questions@freebsd.org Thu Jan 31 20:44:15 2019 Return-Path: Delivered-To: freebsd-questions@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 0B06114B73D3 for ; Thu, 31 Jan 2019 20:44:15 +0000 (UTC) (envelope-from asv@inhio.net) Received: from cz-prg-mx-01.inhio.net (mail.inhio.net [178.238.36.226]) by mx1.freebsd.org (Postfix) with ESMTP id CC0997117E for ; Thu, 31 Jan 2019 20:44:13 +0000 (UTC) (envelope-from asv@inhio.net) Received: from titanio (titanio.inhio.net [10.0.0.21]) by cz-prg-mx-01.inhio.net (Postfix) with ESMTPSA id 3FD4F22F17; Thu, 31 Jan 2019 21:44:10 +0100 (CET) Message-ID: <96a0871e6a30b042378fc5526a70a8ccfa803ef6.camel@inhio.net> Subject: Re: PF issue since 11.2-RELEASE From: ASV To: Kristof Provost Cc: questions list Date: Thu, 31 Jan 2019 21:44:06 +0100 In-Reply-To: <20190131112237.GC57976@vega.codepro.be> References: <989e79372513e9769c6857b531f14df8ce0b6f3a.camel@inhio.net> <51F0845A-2BB3-4BC9-977D-BB0E6C305ED3@FreeBSD.org> <20190129193609.GB57976@vega.codepro.be> <20190131112237.GC57976@vega.codepro.be> Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="=-+3SFJ77KJeoql2Q8kE7g" X-Mailer: Evolution 3.28.5 FreeBSD GNOME Team Mime-Version: 1.0 X-Rspamd-Queue-Id: CC0997117E X-Spamd-Bar: --- Authentication-Results: mx1.freebsd.org; spf=pass (mx1.freebsd.org: domain of asv@inhio.net designates 178.238.36.226 as permitted sender) smtp.mailfrom=asv@inhio.net X-Spamd-Result: default: False [-3.45 / 15.00]; ARC_NA(0.00)[]; RCVD_VIA_SMTP_AUTH(0.00)[]; NEURAL_HAM_MEDIUM(-1.00)[-0.997,0]; FROM_HAS_DN(0.00)[]; MV_CASE(0.50)[]; R_SPF_ALLOW(-0.20)[+mx]; MIME_GOOD(-0.20)[multipart/signed,text/plain]; DMARC_NA(0.00)[inhio.net]; NEURAL_HAM_LONG(-1.00)[-1.000,0]; NEURAL_SPAM_SHORT(0.35)[0.348,0]; TO_MATCH_ENVRCPT_SOME(0.00)[]; TO_DN_ALL(0.00)[]; MX_GOOD(-0.01)[cached: mail.inhio.net]; RCPT_COUNT_TWO(0.00)[2]; SIGNED_PGP(-2.00)[]; RCVD_NO_TLS_LAST(0.10)[]; FROM_EQ_ENVFROM(0.00)[]; R_DKIM_NA(0.00)[]; MIME_TRACE(0.00)[0:+,1:+]; ASN(0.00)[asn:24971, ipnet:178.238.32.0/20, country:CZ]; MID_RHS_MATCH_FROM(0.00)[]; IP_SCORE(0.01)[country: CZ(0.03)]; RCVD_COUNT_TWO(0.00)[2] X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 31 Jan 2019 20:44:15 -0000 --=-+3SFJ77KJeoql2Q8kE7g Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Thu, 2019-01-31 at 12:22 +0100, Kristof Provost wrote: > What does pflog show? 00:00:00.000000 rule 25/0(match): pass in on lagg0: 212.83.XXX.XXX.5441 > 1= 00.100.10.XXX.5060: SIP: REGISTER sip:100.100.10.[!sip] 00:00:48.499578 rule 25/0(match): pass in on lagg0: 212.83.XXX.XXX.5457 > 1= 00.100.10.XXX.5060: SIP: REGISTER sip:100.100.10.[!sip] 00:00:48.182323 rule 25/0(match): pass in on lagg0: 212.83.XXX.XXX.5449 > 1= 00.100.10.XXX.5060: SIP: REGISTER sip:100.100.10.[!sip] 00:00:47.866652 rule 25/0(match): pass in on lagg0: 212.83.XXX.XXX.5477 > 1= 00.100.10.XXX.5060: SIP: REGISTER sip:100.100.10.[!sip] 00:00:47.801770 rule 25/0(match): pass in on lagg0: 212.83.XXX.XXX.5484 > 1= 00.100.10.XXX.5060: SIP: REGISTER sip:100.100.10.[!sip] 00:00:48.091841 rule 25/0(match): pass in on lagg0: 212.83.XXX.XXX.5594 > 1= 00.100.10.XXX.5060: SIP: REGISTER sip:100.100.10.[!sip] By the way, among my tests I've discovered that connectivity issues re- occur as soon as I mix network ranges and IP addresses within the same table (not even pf restart seems to make it work properly again). I used to have a script to populate a separate table with the spammers and from time to time I was adding network ranges when multiple (many) IP addresses within the same range were bombing me so I know it worked pretty well .... even when IP addresses were overlapping already specified ranges. Ex. 120.30.0.0/24 213.156.32.2 ......... ......... --=-+3SFJ77KJeoql2Q8kE7g Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part Content-Transfer-Encoding: 7bit -----BEGIN PGP SIGNATURE----- iQEzBAABCgAdFiEE5dE8BwbhhcQw2TsezaQsUNd+zIkFAlxTXhYACgkQzaQsUNd+ zImwZQgApr10fMHs/xVO2wQV+fbxOG33bgYEpOlnLIEhkbRcuBAqFcog0c/JPlot YV/RV61aByuloAls4KjpZjW9oJ9wwG8diAL4Hk6uBhFShehiPTXp6BIHap61lgTw 0kewOoLBrhkq/+5C/JcFtilayitpb76qbeSATAiUJhzMvqFdUA+J1BaSfvO/qDxM 8N0dcQzZsqdbYQwZfDx8xuXuge+Sx8fHyxttAE7hyMxkFtKqhBRqVUEzEbJkGQ0Y +4vcxCf9EwajQ9t8lJYk8Xat/G3MM8zUJgH9CBmFYGFPiZ322pu3ezEE8/Pl+8FV f/QAOh5xUv8NAm8H33ZAjG7PyRJHwQ== =6kZ5 -----END PGP SIGNATURE----- --=-+3SFJ77KJeoql2Q8kE7g--