Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 22 Jun 2016 07:12:07 +0000 (UTC)
From:      Danny Rabara <danny@fusionbooks.com.au>
To:        freebsd-questions@freebsd.org
Subject:   Resource Suggestion
Message-ID:  <2067214606.64006.1466579527954.JavaMail.ec2-user@ip-10-153-199-204.ec2.internal>

next in thread | raw e-mail | index | archive | help
Hi there,=20
=20
My name is Danny and I'm part of the team at Fusion Yearbooks. I recently f=
ound this interesting post:=C2=A0lists.freebsd.org/pipermail/freebsd-questi=
ons/2014-March/256980.html and immediately noticed your great interest for =
education=C2=A0and teaching strategies.=20
=20
I immediately thought of sharing to you beautiful article about educational=
 podcast, including various resource podcast available today. We've put tog=
ether this resource to serve as a guide for teachers and educators in utili=
zing podcast=C2=A0as an effective and highly-engaging teaching strategy. He=
re's a link: http://www.fusionyearbooks.com/blog/educational-podcasts/.=20
=20
Hope you like it and if you could also give the resource a simple mention o=
r a share, we would be really grateful.=20
=20
Many Thanks!=20
=20
Danny Rabara Jr.=20
Community Outreach Specialist=20
@FusionYearbooks ( http://www.fusionyearbooks.com/ )
From owner-freebsd-questions@freebsd.org  Wed Jun 22 07:53:57 2016
Return-Path: <owner-freebsd-questions@freebsd.org>
Delivered-To: freebsd-questions@mailman.ysv.freebsd.org
Received: from mx1.freebsd.org (mx1.freebsd.org
 [IPv6:2001:1900:2254:206a::19:1])
 by mailman.ysv.freebsd.org (Postfix) with ESMTP id CA844B03232
 for <freebsd-questions@mailman.ysv.freebsd.org>;
 Wed, 22 Jun 2016 07:53:57 +0000 (UTC)
 (envelope-from carlopmart@gmail.com)
Received: from mail-lb0-x235.google.com (mail-lb0-x235.google.com
 [IPv6:2a00:1450:4010:c04::235])
 (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
 (Client CN "smtp.gmail.com",
 Issuer "Google Internet Authority G2" (verified OK))
 by mx1.freebsd.org (Postfix) with ESMTPS id 4EE8D20A2
 for <freebsd-questions@freebsd.org>; Wed, 22 Jun 2016 07:53:57 +0000 (UTC)
 (envelope-from carlopmart@gmail.com)
Received: by mail-lb0-x235.google.com with SMTP id xp5so17364701lbb.0
 for <freebsd-questions@freebsd.org>; Wed, 22 Jun 2016 00:53:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;
 h=date:from:to:subject:message-id:mime-version:content-disposition
 :user-agent; bh=mno5UUP7PHTbk5K6CitpeUtgALprj7IBqKHGOQSQsRQ=;
 b=TxQh21gaXXAUx4u9zOzQJWsR/wJ4tC3lz9lzfJBX4eJhVp6kmWWW1pOvVMrHvV0zIA
 s+kojob2ymClTMNCJa+gEvp9pz9MdQpksp+bo1dQI2JH1kctyUQPO4FbF/s/NoLy2S0A
 fb0d4AerFYTq4g9ZGnkkoqRoUzC2sLBxrNt2/zpVAXukil2WwsKOR+jYiPHDWZzvsQji
 vPtjcxYpyI1e4GjVB36TVCcPj5a8aovhpOOPzn/SKbgS7CXC7zhPbvI8kADKduM+4OIj
 olSKG40kA4+sYOy8eYu7txbfGy1/R2upU6/v1dW4XvTZg4WL0oSLzHnBiu2PMYRWnEzq
 SozQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20130820;
 h=x-gm-message-state:date:from:to:subject:message-id:mime-version
 :content-disposition:user-agent;
 bh=mno5UUP7PHTbk5K6CitpeUtgALprj7IBqKHGOQSQsRQ=;
 b=cvdySZTxAkbMnCCQzoxdj2yMfiXcbPV0mVH3+aPuLz6C2+ZA4O8GWCkR163OuSPjXx
 1N+ylcTSpNGj0vH40dq6K/NdSHb5WIbt4PlWYW/5iwhV616ovOS+4oA7dpJQCkBim7uN
 IhFtXqw8LriadwyeedXdIJvKHOM+ezfeC9zEE/hUcQ2UHmnOzu0tM3BJesiiPAViF5Xy
 q9O01Y7BkUsYZk9wb4LVrTo8XJphSO3tv1QJ9RyEYAaWT6Yk0D60ENc0hEt17V4X7Y0g
 I9CfBceQLSyXWKmADEq24TFDDZaPnmJdsAzuIPlzAALeZWHp1MJb1TmzvhHgq1k1P/Wd
 sKnA==
X-Gm-Message-State: ALyK8tLn1SXkVcD+/Etxh6VmHvEXp6oHvwcMxgDL2m2lisAknEoTpEgkbHOiUM8nmOgqCA==
X-Received: by 10.194.79.228 with SMTP id m4mr9459246wjx.171.1466582035104;
 Wed, 22 Jun 2016 00:53:55 -0700 (PDT)
Received: from beagle.bcn.sia.es (132.red-79-154-242.dynamicip.rima-tde.net.
 [79.154.242.132])
 by smtp.gmail.com with ESMTPSA id d4sm3223451wjb.47.2016.06.22.00.53.53
 for <freebsd-questions@freebsd.org>
 (version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256);
 Wed, 22 Jun 2016 00:53:54 -0700 (PDT)
Date: Wed, 22 Jun 2016 07:53:47 +0000
From: "C. L. Martinez" <carlopmart@gmail.com>
To: freebsd-questions@freebsd.org
Subject: Strange behavior with DNS requests under FreeBSD 10.3 with pf enabled
Message-ID: <20160622075347.GA5205@beagle.bcn.sia.es>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
User-Agent: Mutt/1.6.0 (2016-04-01)
X-BeenThere: freebsd-questions@freebsd.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: User questions <freebsd-questions.freebsd.org>
List-Unsubscribe: <https://lists.freebsd.org/mailman/options/freebsd-questions>, 
 <mailto:freebsd-questions-request@freebsd.org?subject=unsubscribe>
List-Archive: <http://lists.freebsd.org/pipermail/freebsd-questions/>;
List-Post: <mailto:freebsd-questions@freebsd.org>
List-Help: <mailto:freebsd-questions-request@freebsd.org?subject=help>
List-Subscribe: <https://lists.freebsd.org/mailman/listinfo/freebsd-questions>, 
 <mailto:freebsd-questions-request@freebsd.org?subject=subscribe>
X-List-Received-Date: Wed, 22 Jun 2016 07:53:57 -0000

Hi all,

 I have detected a stange behavior with my FreeBSD 10.3 (fully patched) PF based firewall. With some dns requests, pf denies the connection, but with others not. For example, if I do a query about www.oracle.com or www.microsfot.com for example, all works ok. But if I do a query about www.freebsd.org or www.openbsd.org, request is denied:

00:00:02.610710 rule 29..16777216/0(match): block in on vtnet1: (tos 0x0, ttl 52, id 23787, offset 0, flags [+], proto UDP (17), length 1492)
    8.8.8.8.53 > 172.30.77.2.50068: 5832$ 7/0/1 org. DNSKEY, org. DNSKEY, org. DNSKEY, org. DNSKEY, org. RRSIG, org. RRSIG, org. RRSIG[|domain]
00:00:27.493700 rule 29..16777216/0(match): block in on vtnet1: (tos 0x0, ttl 54, id 38872, offset 0, flags [+], proto UDP (17), length 1492)
    8.8.8.8.53 > 172.30.77.2.64953: 20142$ 7/0/1 org. DNSKEY, org. DNSKEY, org. DNSKEY, org. DNSKEY, org. RRSIG, org. RRSIG, org. RRSIG[|domain]
00:00:02.699902 rule 29..16777216/0(match): block in on vtnet1: (tos 0x0, ttl 52, id 41109, offset 0, flags [+], proto UDP (17), length 1492)
    8.8.8.8.53 > 172.30.77.2.59317: 29961$ 7/0/1 org. DNSKEY, org. DNSKEY, org. DNSKEY, org. DNSKEY, org. RRSIG, org. RRSIG, org. RRSIG[|domain]
00:00:27.482112 rule 29..16777216/0(match): block in on vtnet1: (tos 0x0, ttl 54, id 46875, offset 0, flags [+], proto UDP (17), length 1492)
    8.8.4.4.53 > 172.30.77.2.65447: 9845$ 7/0/1 org. DNSKEY, org. DNSKEY, org. DNSKEY, org. DNSKEY, org. RRSIG, org. RRSIG, org. RRSIG[|domain]
00:00:00.280886 rule 29..16777216/0(match): block in on vtnet1: (tos 0x0, ttl 54, id 12677, offset 0, flags [+], proto UDP (17), length 1492)
    8.8.8.8.53 > 172.30.77.2.58368: 4177$ 7/0/1 org. DNSKEY, org. DNSKEY, org. DNSKEY, org. DNSKEY, org. RRSIG, org. RRSIG, org. RRSIG[|domain]
00:00:02.421382 rule 29..16777216/0(match): block in on vtnet1: (tos 0x0, ttl 52, id 57858, offset 0, flags [+], proto UDP (17), length 1492)
    8.8.4.4.53 > 172.30.77.2.61071: 62867$ 7/0/1 org. DNSKEY, org. DNSKEY, org. DNSKEY, org. DNSKEY, org. RRSIG, org. RRSIG, org. RRSIG[|domain]

 It is really strange. I am using an internal unbound dns cache server installed on a Debian host and I have configured Google's DNS servers, 8.8.8.8 and 8.8.4.4, as a forwarders. I have tried to disable these forwarders in unbound's config, but same error occurs.

 Any idea why??

 Thanks.
-- 
Greetings,
C. L. Martinez



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?2067214606.64006.1466579527954.JavaMail.ec2-user>