From owner-freebsd-stable@FreeBSD.ORG Tue Sep 11 15:18:05 2012 Return-Path: Delivered-To: freebsd-stable@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 77D3D1065715 for ; Tue, 11 Sep 2012 15:18:04 +0000 (UTC) (envelope-from allbery.b@gmail.com) Received: from mail-qa0-f54.google.com (mail-qa0-f54.google.com [209.85.216.54]) by mx1.freebsd.org (Postfix) with ESMTP id A9D9A8FC17 for ; Tue, 11 Sep 2012 15:18:03 +0000 (UTC) Received: by qatn12 with SMTP id n12so426920qat.13 for ; Tue, 11 Sep 2012 08:17:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=EzKAtGJ75VzmMq2enLQ8eOLYnZINBAgS2Dkqe0oY9cg=; b=eCQFz4FX2H1L0QkRMhTfR1YzjBgKDCsUp2J7FOCs1Lt6RIUi/m/UqZOaVZSnp/t1A2 U7v45yX/ciuZhzA9615Yg4yVJRxKg+91ZCvXQbeLgWfnl3ZbkBufx8Ov3Sp0EHBVx6oz /kpggQhd28yI6iwvitl/qWp5ZBOGPMZlCK7O2MKGmwJTg22LmonIDbdD5xIWlb7zAymo 3EmEUVjGeUl8sO6DtKGhnn6yn/hChmSzlh3pxVgzKsU7GAkuPDlIBZVKObLszHDjVgL0 X6cpOUL2kHOdzcBOJ5pqu4JymFOLBX5oLFLgtgvhWX+0dnP244M9Yc3KvuK0EwLCdIvk Nhrw== MIME-Version: 1.0 Received: by 10.229.136.145 with SMTP id r17mr4783878qct.43.1347376677484; Tue, 11 Sep 2012 08:17:57 -0700 (PDT) Received: by 10.49.95.230 with HTTP; Tue, 11 Sep 2012 08:17:57 -0700 (PDT) In-Reply-To: References: <504EF33A.7080304@digital-infotech.net> Date: Tue, 11 Sep 2012 11:17:57 -0400 Message-ID: From: Brandon Allbery To: Kimmo Paasiala Content-Type: text/plain; charset=UTF-8 X-Content-Filtered-By: Mailman/MimeDel 2.1.5 Cc: "Shiv. Nath" , "freebsd-stable@freebsd.org" Subject: Re: PF Configuration - FreeBSD Release 9.0 x64 X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 11 Sep 2012 15:18:05 -0000 On Tue, Sep 11, 2012 at 11:12 AM, Kimmo Paasiala wrote: > On Tue, Sep 11, 2012 at 6:05 PM, Brandon Allbery > wrote: > > On Tue, Sep 11, 2012 at 4:26 AM, Damien Fleuriot wrote: > >> On 11 Sep 2012, at 10:15, "Shiv. Nath" > >> wrote: > >> It says it received a *response* so my understanding is *you* are trying > >> to connect. > > > > But it's avahi (a zeroconf implementation) so the response is to a > > broadcast; the remote machine in question may also be broadcasting. > > > > I would actually question why avahi is even enabled on a server; perhaps > > the correct answer is simply to disable it in rc.conf. > > You do know that avahi-daemon's main use is to advertise _services_ > running on a host? > Yes, but zeroconf-style services are often more of a peer-to-peer nature instead of fixed (which don't *need* zeroconf). It's also a larger attack surface. -- brandon s allbery allbery.b@gmail.com wandering unix systems administrator (available) (412) 475-9364 vm/sms