pf.conf

  1. N

    PF PF firewall pf.conf Review

    Hi all, Could somebody with some knowledge and experience have a look at my pf.conf before I start using it, to make sure I'm not doing anything stupid with it? I am using FreeBSD 12.2 on a laptop connected via wifi to my ISP router and the VPN provided for work. I am using OpenVPN and...
  2. F

    PF Packet tagging with route-to in pf.conf

    nat log (to pflog0) on if0 from 192.168.0.1 tag TAG_PASS tagged TAG_EX -> (if0) label "test" nat log (to pflog0) on if0 from 192.168.0.1 tag TAG_PASS tagged TAG_EX -> (if0) label "test" nat log (to pflog0) on if0 from 192.168.0.1 tag TAG_PASS tagged TAG_EX -> (if0) label "test" no nat from...
  3. Killua

    PF GeoIP whitelist or blacklist of states

    Hi Guys, i don't find nothing on the net about GeoIP for PF, I searched a lot but nothing, I need to block states or create a white list of states that can access the server so I can make things easier for myself, could anyone help me? place here at the bottom of my pf configuration that is...
  4. S

    PF PF Portfowarding HTTP Sometimes can be opened sometime can't be opened

    Hello everyone. to the point, I would to ask something about port portforwarding. is portforwarding very slow connection? My friends opened my server actually is really fast (about 20ms). But when I opened it, it is very slow to opened the web from the my ip public. sometime when I opened it is...
  5. K

    Solved Gnus gmail stops working

    Hello, This morning I found sending gmail emails via Gnus stopped working. It used to be working since I checked my Gnus 'sent' folder and there are mails I sent several months ago. Gnus/5.13 (Gnus v5.13) Emacs/26.1 (berkeley-unix) Sending via mail... network-stream-open-starttls: make client...
  6. blueCub

    Solved Help Getting PF to work with my Git Jail

    Hi all, I have an issue with my PF rules and I would like to understand why this is happening and how to solve it. I have very basic knowledge of PF and this is kind of learning curve for me. I have gitea server https://www.freshports.org/www/gitea/ running inside a jail in a vm. It works...
  7. R

    PF PF config for double NAT jail host

    I think that I'm being somewhat ambitious and I'm finding that I'm getting some horrible issues as a result. Firstly, what I'm trying to achieve. The way that I have tried to set up this network in the past was that the router was in the DMZ and that it passed some traffic (HTTP/S) through to...
  8. Eric A. Borisch

    PF Why my pf would not load on boot

    Total head-smacker, but for posterity (and for the next poor sap googling "pf won't start at boot") Do not use hostnames in your pf.conf or any tables loaded by your configuration. While it is not invalid, and will work just fine with a pfctl -nf /etc/pf.conf check of the syntax or a pfctl -f...
  9. m0nkey_

    IPFW Using IPFW to NAT a jail inside a VM == Slow network connectivity inside jail

    I've been pulling my hair out over this for days! I have a VM, jails on a loopback interface and using IPFW to NAT the traffic. My findings show that it slows to a crawl. I've also tested with PF and it works like a charm. Network speeds within the jail are fine. I've tested this on Vultr...
  10. S

    PF 11.1 / ALTQ / pf / ixgbe

    All, Any update as to whether ALTQ (with PF) will be supported with ixgbe cards (or not)? Have been hoping that some traction may have been gained, but haven't been able to use this functionality for quite a few versions. FYI - the manual page for ALTQ lists ixgbe as "supported", but get the...
  11. L

    This weird PF

    Hey Guys. Following problem: Inside a jail I can ping my nameserver, i can ping someones ip adress but I cant ping a domain name. I cant install pkg or anything else inside a jail, because its not working. I set up my jails with ezjail. I created a fresh jail but its not working. I have set my...
  12. D

    PF Route outgoing smtp through pptp tunnel

    I am using freeBSD 11.1-RELEASE-p6 on a raspberry PI and I can't get it to route email out though a pptp tunnel instead of the default route through the ethernet connection. If I change smtp_bind_address in postfix main.cf to the pptp tunnel address I can see the correct from address in pflog...
  13. A

    PF pf.conf and local redirection to domain

    Hi, How to properly redirect traffic from local network to domain. I have nginx, php, mysql, wordpress etc. When I am trying to open website not in wordpress using set domain it won't open, but outside network people can open without any issues. When trying to open on local address it works...
  14. A

    PF pf.conf and Network issue

    Hi, Quick question. What could be the issue why I cannot ping my jail from local machine or local machine from jail? I thought it is pf.conf rdr somewhere wrong but now I am thinking about routing table not right. I can access anything from outside to jail. I have teamspeak3 server and if I...
  15. blueCub

    Solved PF block not stopping access to my jail

    Hello there, I have a jail inside a VM. I installed Gitea inside the Jail and configured PF (nat) to forward traffic coming on port 2000 to the jail port 3000 (The gitea web application) and left port 10000 for the ssh (for git) inside the jail. All is okay so far till recently I checked my...
  16. P

    PF I have issues with the pf.conf being loaded

    I am new to Linux/BSD. I am using FREEBSD 11 . Whenever I try to initiate PF with the pf.conf as below, it gives the error as in the image. I have loaded a custom kernel as shown in altq(4). My pf.conf is, pass inet proto icmp from any to any pass log (all) proto icmp from any to any altq...
  17. P

    PF I have issues with the pf.conf being loaded

    I am new to Linux/BSD. I am using a Debian system with a KFreeBSD kernel. Whenever I try to initiate PF with the pf.conf as below, it gives the error as in the image. My pf.conf is, pass inet proto icmp from any to any pass log (all) proto icmp from any to any altq on le0 cbq bandwidth 500Kb...
  18. big_girl

    PF pf syntax for tables

    After looking here, I'm getting some unexpected errors in a simple pf.conf while just trying to use tables correctly- cat /etc/pf.conf table <martians> const { 0.0.0.0/8, 100.64.0.0/10, 127.0.0.0/8 } table <martians_10> const { 10.0.0.0/8 } table <martians_169> const { 169.254.0.0/16 } pfctl...
  19. K

    PF Firewall in OpenVPN client mode can't do port forwarding

    I have a FreeBSD firewall/router using PF with OpenVPN configured as client mode so that all my traffic goes through the vpn connection via the vpn provider. When the OpenVPN connection is active on my firewall I can't get port forwarding to work properly on the internet facing interface, this...
  20. F

    Solved NAT attribution, I Guess ?

    Hello everyone, I'm new in the word of FreeBSD and more on firewall ... I'm struggle with building a good pf.conf in order to run plex media server inside a jail. I don't know if I'm in the right topic, but after many try I guess is due to pf rules. So here is my /etc/rc.conf...
Top