From owner-freebsd-pf@FreeBSD.ORG Thu Nov 10 21:21:28 2005 Return-Path: X-Original-To: freebsd-pf@freebsd.org Delivered-To: freebsd-pf@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id BB7B216A420 for ; Thu, 10 Nov 2005 21:21:28 +0000 (GMT) (envelope-from solinym@gmail.com) Received: from wproxy.gmail.com (wproxy.gmail.com [64.233.184.198]) by mx1.FreeBSD.org (Postfix) with ESMTP id B262D43D70 for ; Thu, 10 Nov 2005 21:21:26 +0000 (GMT) (envelope-from solinym@gmail.com) Received: by wproxy.gmail.com with SMTP id i5so177386wra for ; Thu, 10 Nov 2005 13:21:26 -0800 (PST) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=AtzAcpLkG2rXE6EgqYRfBTT242F97YQzfOBGKF0AWCgrDzsPSvrAfK5+OI1gte7dMGnndD5dDpHAeXpZZ9uZWKrIV7t8kHAO6nDrJoex1FPAeB3Z/EpvpOSFwm5Hq9q/su0ExL8+Qb3SRlD+iSPNiVxs9+BYlTMLT44GsDR0i4g= Received: by 10.54.150.12 with SMTP id x12mr256407wrd; Thu, 10 Nov 2005 13:21:26 -0800 (PST) Received: by 10.54.81.15 with HTTP; Thu, 10 Nov 2005 13:21:26 -0800 (PST) Message-ID: Date: Thu, 10 Nov 2005 15:21:26 -0600 From: "Travis H." To: Dave In-Reply-To: <003301c5e0f6$6ce6d150$0900a8c0@satellite> MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Content-Disposition: inline References: <003301c5e0f6$6ce6d150$0900a8c0@satellite> Cc: freebsd-pf@freebsd.org Subject: Re: pf and dhcp client or isp? X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 10 Nov 2005 21:21:28 -0000 Well it looks good, at least the DHCP rule seems to allow it in. Have you checked to see if the DHCP server address is valid? RR tends to renumber internal hosts quite a bit (and use RFC1918 addresses for some of their servers). -- http://www.lightconsulting.com/~travis/ -><- "We already have enough fast, insecure systems." -- Schneier & Ferguson GPG fingerprint: 50A1 15C5 A9DE 23B9 ED98 C93E 38E9 204A 94C2 641B