From owner-freebsd-questions@FreeBSD.ORG Thu Aug 7 18:57:41 2008 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 3A44F106568A for ; Thu, 7 Aug 2008 18:57:41 +0000 (UTC) (envelope-from cswiger@mac.com) Received: from mail-out3.apple.com (mail-out3.apple.com [17.254.13.22]) by mx1.freebsd.org (Postfix) with ESMTP id 20A7F8FC2A for ; Thu, 7 Aug 2008 18:57:41 +0000 (UTC) (envelope-from cswiger@mac.com) Received: from relay12.apple.com (relay12.apple.com [17.128.113.53]) by mail-out3.apple.com (Postfix) with ESMTP id 06B0135B34F2; Thu, 7 Aug 2008 11:57:41 -0700 (PDT) Received: from relay12.apple.com (unknown [127.0.0.1]) by relay12.apple.com (Symantec Mail Security) with ESMTP id E00F9464011; Thu, 7 Aug 2008 11:57:40 -0700 (PDT) X-AuditID: 11807135-a4defbb000001321-37-489b45a4c792 Received: from cswiger1.apple.com (cswiger1.apple.com [17.227.140.124]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by relay12.apple.com (Apple SCV relay) with ESMTP id C3D05420005; Thu, 7 Aug 2008 11:57:40 -0700 (PDT) Message-Id: <0C465144-E873-4D87-B22E-4C5F6CB936B2@mac.com> From: Chuck Swiger To: kalin m In-Reply-To: <489B3FFD.308@el.net> Content-Type: text/plain; charset=US-ASCII; format=flowed; delsp=yes Content-Transfer-Encoding: 7bit Mime-Version: 1.0 (Apple Message framework v928.1) Date: Thu, 7 Aug 2008 11:57:40 -0700 References: <489A8EA3.5030102@el.net> <489B3FFD.308@el.net> X-Mailer: Apple Mail (2.928.1) X-Brightmail-Tracker: AAAAAA== Cc: freebsd-questions@freebsd.org Subject: Re: Remote host replies to SYN+FIN X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 07 Aug 2008 18:57:41 -0000 On Aug 7, 2008, at 11:33 AM, kalin m wrote: > does anybody have any idea how to resolve this? > > thanks.. > > kalin m wrote: >> hi all... >> after setting up a pf rule set on one of newly installed freebsd 7 >> i did a scan with nessus 3 on that machine >> >> the result i got was like this one: >> http://www.nessus.org/plugins/index.php?view=single&id=11618 how do >> 'fix' it using pf?... Add a pf rule like to pf.conf: block in proto tcp from any flags SF/SF ...? -- -Chuck