From owner-freebsd-pf@FreeBSD.ORG Wed Mar 26 15:02:06 2008 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 839651065686 for ; Wed, 26 Mar 2008 15:02:06 +0000 (UTC) (envelope-from dalibor.gudzic@gmail.com) Received: from gv-out-0910.google.com (gv-out-0910.google.com [216.239.58.186]) by mx1.freebsd.org (Postfix) with ESMTP id 07AD58FC26 for ; Wed, 26 Mar 2008 15:02:05 +0000 (UTC) (envelope-from dalibor.gudzic@gmail.com) Received: by gv-out-0910.google.com with SMTP id n40so836659gve.39 for ; Wed, 26 Mar 2008 08:02:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:references; bh=9cyofqGerH3MCZNEmU1Fp6TpYjxSHtFUloY0+zgfcRs=; b=rUP6jYEKKQPUtzCbJ8WdfPShPWlgWxn5vQHLR/HZSCujMmwC7aWaCde+ynQIqjGYmnVDBQJCbxG6683Ddlx/1CrZW9wLfHTdUrl0hDHgLUSalj98BmFCqYFUgvdDwHODVEuxK9GhHmwOIIEYHoTp8ZLcB+P9ZpTVN08rWDw98fs= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:references; b=RJbLMdxt5w/gJPKE2TWEv28ZGuEr0BhnHdqgbk6EyFN6y3UM9myI1YBR/NE8rf/HM2mmiX3OMNKdX6T/24GhHzHmUsAcAF5nOppt2A2P41TkJUs3qQ5i+xQrTpzgd3xSwI5/UpwbAq2RqD5et/2wq1LgLjTVH2XNY2k313wk6pY= Received: by 10.150.158.8 with SMTP id g8mr91063ybe.25.1206543722379; Wed, 26 Mar 2008 08:02:02 -0700 (PDT) Received: by 10.150.228.11 with HTTP; Wed, 26 Mar 2008 08:02:02 -0700 (PDT) Message-ID: <866fa9520803260802v3686b24dq1ee7aa1cc4b35f75@mail.gmail.com> Date: Wed, 26 Mar 2008 16:02:02 +0100 From: "Dalibor Gudzic" To: "Jeremy Chadwick" In-Reply-To: <20080326025316.GA68607@eos.sc1.parodius.com> MIME-Version: 1.0 References: <9DE6EC5B5CF8C84281AE3D7454376A0D6D0290@cetus.dawnsign.com> <20080326025316.GA68607@eos.sc1.parodius.com> Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Content-Disposition: inline X-Content-Filtered-By: Mailman/MimeDel 2.1.5 Cc: Greg Hennessy , freebsd-pf@freebsd.org Subject: Re: Bacula File/Storage Connection Woes using PF X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 26 Mar 2008 15:02:06 -0000 On Wed, Mar 26, 2008 at 3:53 AM, Jeremy Chadwick wrote: > I'll try to explain it with a very small ruleset and a couple scenarios: > > $ext_if = network interface that's got a public IP address > 4.4.4.4 = our public IP address > > pass out quick all flags S/SA keep state > pass out quick all > block in log all > pass in quick on $ext_if inet proto tcp from any to 4.4.4.4 port ssh > > Two scenarios: > > 1) When an incoming TCP packet from to 4.4.4.4 on port 22 is seen, > that incoming packet is permitted (rule #4). Outbound responses from > 4.4.4.4 to are also > permitted (rule #1). Note the "keep state". > > > Correct me if I'm wrong, but I think the outbound packet will be matched against the #2 rule, as the rule #1 has "flags S/SA" and will not match the packet since the packet would have "ACK" flag set. Thus, the state will not be created in state table. That is if the rule #4 doesn't include "keep state" (which is default in RELENG_7).