From owner-freebsd-questions@freebsd.org Wed Feb 6 14:48:40 2019 Return-Path: Delivered-To: freebsd-questions@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id A8DB614D5C1E for ; Wed, 6 Feb 2019 14:48:40 +0000 (UTC) (envelope-from byrnejb@harte-lyne.ca) Received: from mx32.harte-lyne.ca (mx32.harte-lyne.ca [216.185.71.32]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "mx32.harte-lyne.ca", Issuer "CA_HLL_ISSUER_2016" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 1218470342 for ; Wed, 6 Feb 2019 14:48:29 +0000 (UTC) (envelope-from byrnejb@harte-lyne.ca) Received: from mx32.harte-lyne.ca (unknown [127.0.32.1]) by mx32.harte-lyne.ca (Postfix) with ESMTP id BAC79C734 for ; Wed, 6 Feb 2019 09:48:28 -0500 (EST) X-Virus-Scanned: amavisd-new at harte-lyne.ca Received: from mx32.harte-lyne.ca ([127.0.32.1]) by mx32.harte-lyne.ca (mx32.harte-lyne.ca [127.0.32.1]) (amavisd-new, port 10024) with ESMTP id XP11yOXxSffg for ; Wed, 6 Feb 2019 09:48:21 -0500 (EST) Received: from webmail.harte-lyne.ca (mx32.harte-lyne.ca [216.185.71.32]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mx32.harte-lyne.ca (Postfix) with ESMTPSA id 685F6C729 for ; Wed, 6 Feb 2019 09:48:21 -0500 (EST) Received: from 216.185.71.44 (SquirrelMail authenticated user byrnejb_hll) by webmail.harte-lyne.ca with HTTP; Wed, 6 Feb 2019 09:48:21 -0500 Message-ID: <08dc977729b0176043c84e504df84f95.squirrel@webmail.harte-lyne.ca> Date: Wed, 6 Feb 2019 09:48:21 -0500 Subject: pf filter settings From: "James B. Byrne" To: freebsd-questions@freebsd.org Reply-To: byrnejb@harte-lyne.ca User-Agent: SquirrelMail/1.4.23 [SVN] MIME-Version: 1.0 Content-Type: text/plain;charset=iso-8859-1 Content-Transfer-Encoding: 8bit X-Priority: 3 (Normal) Importance: Normal X-Rspamd-Queue-Id: 1218470342 X-Spamd-Bar: -------- X-Spamd-Result: default: False [-8.48 / 15.00]; RCVD_VIA_SMTP_AUTH(0.00)[]; HAS_REPLYTO(0.00)[byrnejb@harte-lyne.ca]; RBL_COMPOSITE_RCVD_IN_DNSWL_MED_DWL_DNSWL_LOW(0.00)[]; R_SPF_ALLOW(-0.20)[+ip4:216.185.71.0/26]; TO_DN_NONE(0.00)[]; RCVD_DKIM_ARC_DNSWL_MED(-0.50)[]; REPLYTO_ADDR_EQ_FROM(0.00)[]; DKIM_TRACE(0.00)[harte-lyne.ca:+]; RCVD_IN_DNSWL_MED(-0.20)[32.71.185.216.list.dnswl.org : 127.0.4.2]; HAS_X_PRIO_THREE(0.00)[3]; MX_GOOD(-0.01)[mx32.harte-lyne.ca,mx31.harte-lyne.ca,mx132.harte-lyne.ca]; DMARC_POLICY_ALLOW(-0.50)[harte-lyne.ca,quarantine]; NEURAL_HAM_SHORT(-0.99)[-0.986,0]; FROM_EQ_ENVFROM(0.00)[]; MIME_TRACE(0.00)[0:+]; RCVD_TLS_LAST(0.00)[]; ASN(0.00)[asn:12021, ipnet:216.185.64.0/20, country:CA]; IP_SCORE(-3.78)[ip: (-9.91), ipnet: 216.185.64.0/20(-4.95), asn: 12021(-3.96), country: CA(-0.09)]; ARC_NA(0.00)[]; NEURAL_HAM_MEDIUM(-1.00)[-1.000,0]; R_DKIM_ALLOW(-0.20)[harte-lyne.ca:s=dkim_hll]; RCVD_COUNT_FIVE(0.00)[5]; FROM_HAS_DN(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; NEURAL_HAM_LONG(-1.00)[-1.000,0]; MIME_GOOD(-0.10)[text/plain]; PREVIOUSLY_DELIVERED(0.00)[freebsd-questions@freebsd.org]; RCPT_COUNT_ONE(0.00)[1]; DWL_DNSWL_LOW(0.00)[harte-lyne.ca.dwl.dnswl.org : 127.0.4.1] X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 06 Feb 2019 14:48:40 -0000 I have these rules in a pf.conf in this order: ### Define interfaces ### External ext_if="em1" ### Internal int_if="em0" . . . ### Allow our networks to operate # Pass packets sent to me on local interface pass log quick on $int_if \ from { self $int_if:network } \ to { self $int_if:network } . . . ### set default action to block everything block return out log all block drop in log all . . . ifconfig em0 shows this: . . . inet 216.185.71.1 netmask 0xffffff80 broadcast 216.185.71.127 inet 192.168.216.1 netmask 0xffffff00 broadcast 192.168.216.255 . . . When I connect to 192.168.216.31 from 216.185.71.44 I see this in pflog: 00:00:00.061438 rule 241/0(match): pass in on em0: 216.185.71.44.17457 > 192.168.216.31.22: Flags [S], seq 3972256681, win 65535, options [mss 1440,nop,wscale 6,sackOK,TS val 670920488 ecr 0], length 0 00:00:00.000028 rule 241/0(match): pass out on em0: 216.185.71.44.17457 > 192.168.216.31.22: Flags [S], seq 3972256681, win 65535, options [mss 1440,nop,wscale 6,sackOK,TS val 670920488 ecr 0], length 0 00:00:00.023502 rule 499/0(match): block in on em0: 216.185.71.44.17457 > 192.168.216.31.22: Flags [P.], seq 108:144, ack 1, win 1030, options [nop,nop,TS val 670996382 ecr 2400903835], length 36 00:00:00.099675 rule 499/0(match): block in on em0: 216.185.71.44.17457 > 192.168.216.31.22: Flags [P.], seq 0:144, ack 1, win 1030, options [nop,nop,TS val 671001431 ecr 2400903835], length 144 What is going on? Why is the rule 'block drop in log all' have effect and the rule pass log quick on $int_if \ from { self $int_if:network } \ to { self $int_if:network } does not, despite the quick option and the fact that it occurs first. I then tried these rules: pass log quick on $int_if \ from $net_internal \ to any pass log quick on $int_if \ from any \ to $net_internal where $net_internal resolves to all of the networks used on the lan. This does not work either. SSH connections hang after a brief period because the 'block in all' rule gets triggered. What I want to accomplish is to simply pass all internal traffic along int_if without filtering it but still filter lan traffic passing through the gateway. What rule accomplishes this n PF? -- *** e-Mail is NOT a SECURE channel *** Do NOT transmit sensitive data via e-Mail Do NOT open attachments nor follow links sent by e-Mail James B. Byrne mailto:ByrneJB@Harte-Lyne.ca Harte & Lyne Limited http://www.harte-lyne.ca 9 Brockley Drive vox: +1 905 561 1241 Hamilton, Ontario fax: +1 905 561 0757 Canada L8E 3C3 -- *** e-Mail is NOT a SECURE channel *** Do NOT transmit sensitive data via e-Mail Do NOT open attachments nor follow links sent by e-Mail James B. Byrne mailto:ByrneJB@Harte-Lyne.ca Harte & Lyne Limited http://www.harte-lyne.ca 9 Brockley Drive vox: +1 905 561 1241 Hamilton, Ontario fax: +1 905 561 0757 Canada L8E 3C3 -- *** e-Mail is NOT a SECURE channel *** Do NOT transmit sensitive data via e-Mail Do NOT open attachments nor follow links sent by e-Mail James B. Byrne mailto:ByrneJB@Harte-Lyne.ca Harte & Lyne Limited http://www.harte-lyne.ca 9 Brockley Drive vox: +1 905 561 1241 Hamilton, Ontario fax: +1 905 561 0757 Canada L8E 3C3