Hi,
I am translating a pf script from OpenBSD to FreeBSD, my system is
FreeBSD xxxx 12.0-RELEASE-p6 FreeBSD 12.0-RELEASE-p6 GENERIC amd64
I encountered an issue which I do not understand, in any case please excuse me for this newbie's question. What I "discovered" is that the following rule works
pass in quick log on $ext proto tcp from <auth> to $host port=22 keep state
while that one which was originally in my OpenBSD system
pass in quick log on $ext proto tcp from <auth> to $host port=22 modulate state
where $host is Y.Y.Y.Y, does not. When trying to ssh Y.Y.Y.Y, in the logs I see
00:00:00.129859 rule 10/0(match): pass in on igb0: X.X.X.X.35302 > Y.Y.Y.Y.22: Flags, seq 1109514304, win 29200, options [mss 1452,sackOK,TS val 564387639 ecr 0,nop,wscale 7], length 0
but finally it ends with "Connection timed out".
When the rule has the "keep state", the connection works fine, and the log entry is, probably as expected the same
00:00:01.285639 rule 10/0(match): pass in on igb0: X.X.X.X.35326 > Y.Y.Y.Y.22: Flags , seq 2599461406, win 29200, options [mss 1452,sackOK,TS val 564737097 ecr 0,nop,wscale 7], length 0
May you provide a hint, what is wrong with my setup?
Many thanks,
Dianthus
I am translating a pf script from OpenBSD to FreeBSD, my system is
FreeBSD xxxx 12.0-RELEASE-p6 FreeBSD 12.0-RELEASE-p6 GENERIC amd64
I encountered an issue which I do not understand, in any case please excuse me for this newbie's question. What I "discovered" is that the following rule works
pass in quick log on $ext proto tcp from <auth> to $host port=22 keep state
while that one which was originally in my OpenBSD system
pass in quick log on $ext proto tcp from <auth> to $host port=22 modulate state
where $host is Y.Y.Y.Y, does not. When trying to ssh Y.Y.Y.Y, in the logs I see
00:00:00.129859 rule 10/0(match): pass in on igb0: X.X.X.X.35302 > Y.Y.Y.Y.22: Flags
but finally it ends with "Connection timed out".
When the rule has the "keep state", the connection works fine, and the log entry is, probably as expected the same
00:00:01.285639 rule 10/0(match): pass in on igb0: X.X.X.X.35326 > Y.Y.Y.Y.22: Flags , seq 2599461406, win 29200, options [mss 1452,sackOK,TS val 564737097 ecr 0,nop,wscale 7], length 0
May you provide a hint, what is wrong with my setup?
Many thanks,
Dianthus