The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Top Forums > UNIX for Advanced & Expert Users
.
google unix.com



UNIX for Advanced & Expert Users Expert-to-Expert. Learn advanced UNIX, UNIX commands, Linux, Operating Systems, System Administration, Programming, Shell, Shell Scripts, Solaris, Linux, HP-UX, AIX, OS X, BSD.

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
How to pass option with "at" command? bd9439 UNIX for Dummies Questions & Answers 3 03-24-2008 04:45 PM
Development Releases: Linux Mint 4.0 Beta "Fluxbox", 4.0 Alpha "Debian" iBot UNIX and Linux RSS News 0 01-04-2008 03:00 PM
Explain the line "mn_code=`env|grep "..mn"|awk -F"=" '{print $2}'`" Lokesha UNIX for Dummies Questions & Answers 4 12-20-2007 01:52 AM
how could i make a program mixed with many "|", "<" and ">" strugglingman High Level Programming 2 04-29-2006 09:11 AM
No utpmx entry: you must exec "login" from lowest level "shell" peterpan UNIX for Dummies Questions & Answers 0 01-18-2006 04:15 AM

 
English Japanese Spanish French German Portuguese Italian Dutch Swedish Russian Norwegian Hungarian Hebrew Danish Bulgarian Greek Powered by Powered by Google
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Prev Previous Post   Next Post Next
  #1 (permalink)  
Old 12-24-2003
xyyz xyyz is offline
Registered User
  
 

Join Date: Sep 2001
Posts: 114
Angry pf not working properly even with only "pass in all" and "pass out all" rules

i have two rules in my pf.conf file, "pass in all" and "pass out all"

i was having issues with getting pf working to begin with, so i went with
starting from nothing and working on up.

i have an ultrasparc ultra1 200e, with an added 4-port fast ethernet sbus
card, running "3.4 GENERIC#85 sparc64"

i have my access server on one and my workstation on two separate ports that
are different networks.

i can ping the access server from my workstation and my OBSD box, however, i
can't telnet to the access server from my workstation. i can telnet to the
access server through the OBSD box.

my pf.conf is as follows:


Code:
###################################
# $OpenBSD: pf.conf 11/9/2003
###################################

#####################################
### macros
#####################################

### IP addresses
ext_ip = "10.10.110.2"                          # external interface ip
address
int_ip = "192.168.110.253"                      # internal interface ip
address
pub_ip = "172.16.210.1"                         # public servers interface
ip address
pvt_ip = "192.168.210.1"                        # private servers interface
ip address
pod_ip = "172.16.110.1"                         # cisco router pod interface
ip address

### physical interfaces
int_if = "hme0"                                 # internal interface
pvt_srv_if = "hme1"                             # private server interface
pub_svr_if = "hme2"                             # public server interface
cisco_pod_if = "hme3"                           # router lab interface
ext_if = "hme4"                                 # external interface
all_if = "{ hme0, hme1, hme2, hme3, hme4}"      # all interfaces

### networks
int_net = "192.168.110.240/28"                  # internal LAN
ext_net = "10.10.110.0/30"                      # external LAN
pvt_net = "192.168.210.0/30"                    # private server network
pub_net = "172.16.210.0/30"                     # public server network
pod_net = "172.16.110.0/30"                     # cisco router pod network

### servers
web_server = "172.16.210.2"                     # webserver
PDC = "192.168.210.2"                           # primary domain server
router = "10.10.110.1"                          # router
access_server = "172.16.110.2"                  # cisco pod access server
print_server = "192.168.100.251"                # print server
proxy_server = " 192.168.100.248"               # proxy server

### internal network hosts
venus = "192.168.110.242"                       # ami's system
saturn = "192.168.110.243"                      # my system
mercury = "192.168.110.249"                     # laptop
uranus = "192.168.110.248"                      # backup server
neptune = "192.168.110.253"                     # OpenBSD
hosts = "{" $venus $saturn $mercury $uranus "}"

### Private addresses
spoof_ips= "{ 127.0.0.0/8, 192.168.0.0/16, 172.16.0.0/12, 10.0.0.0/8 }"
# private addresses

### Services
www = "{ 80, 443}"                              # http/https

##################################################################
### Options: tune the behavior of pf
##################################################################

### Sets the interface for which PF should gather statistics such as bytes
in/out and packets passed/blocked
### Optimize PF for one of the following network environments
### packet is silently dropped

# default options
#set require-order yes
#set optimization normal
#set block-policy drop
#set fingerprints "/etc/pf.os"
set loginterface hme4

##########################
###Packet Filtering Table
##########################

### Clean up fragmented packets and abnormal packets
scrub in all fragment reassemble

### redirect/nat rules
nat on $ext_if from any to any -> $ext_ip

###
### traffic rules ###
###

pass in all
pass out all

i'd appreciate any and all help

added code tags for readability --oombera

Last edited by oombera; 02-21-2004 at 02:37 AM..
 

Bookmarks

Tags
ping, ping port, port, port ping

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 03:36 PM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited. Language Translations Powered by .
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2009. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0