From owner-freebsd-current@FreeBSD.ORG Fri Nov 26 20:34:06 2004 Return-Path: Delivered-To: freebsd-current@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 61A7616A4CE; Fri, 26 Nov 2004 20:34:06 +0000 (GMT) Received: from therion.astral-on.net (therion.astral-on.net [193.41.4.2]) by mx1.FreeBSD.org (Postfix) with ESMTP id A7C9343D5A; Fri, 26 Nov 2004 20:34:04 +0000 (GMT) (envelope-from ad@astral-on.net) Received: from odin.astral-on.net (odin.astral-on.net [193.41.4.6]) iAQKXuFs063758; Fri, 26 Nov 2004 22:33:57 +0200 (EET) (envelope-from ad@astral-on.net) Received: from odin.astral-on.net (localhost [127.0.0.1]) by odin.astral-on.net (8.12.8p2/8.12.8) with ESMTP id iAQKXuwk093049; Fri, 26 Nov 2004 22:33:56 +0200 (EET) (envelope-from ad@odin.astral-on.net) Received: (from ad@localhost) by odin.astral-on.net (8.12.8p2/8.12.8/Submit) id iAQKXs5Z093048; Fri, 26 Nov 2004 22:33:55 +0200 (EET) Date: Fri, 26 Nov 2004 22:33:54 +0200 From: Andrew Degtiariov To: freebsd-net@freebsd.org Message-ID: <20041126203354.GB81834@astral-on.net> Mail-Followup-To: freebsd-net@freebsd.org, freebsd-current@freebsd.org Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.5.6i X-Mailman-Approved-At: Sat, 27 Nov 2004 12:56:27 +0000 cc: freebsd-current@freebsd.org Subject: rsh is malfunctioning due to pf X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: ad@astral-on.net List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 26 Nov 2004 20:34:06 -0000 Hello people. I have ipcad installed on 2 PC's running 5.3-RELEASE and 5-STABLE from Nov 21. ipcad (ports/net-mgmt/ipcad) provides ability to control them by rsh (ipcad implement rsh server by yourself). While using pf with primitive rulesets rsh stops its working. It seems like pf drop short packets. Using tcpdump -n -e -ttt -i pflog0 I see: ... 294896 rule 1/3(short): pass out on lo0: IP 127.0.0.1.514 > 127.0.0.1.680: FP 0:387(387) ack 18 win 35840 ... Some parts from pfctl -sa output FILTER RULES: pass in quick all pass out quick all ... Counters match 1319 8.1/s bad-offset 0 0.0/s fragment 0 0.0/s short 192 1.2/s normalize 0 0.0/s memory 0 0.0/s ... -- Andrew Degtiariov DA-RIPE