LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Other *NIX Forums > *BSD
User Name
Password
*BSD This forum is for the discussion of all BSD variants.
FreeBSD, OpenBSD, NetBSD, etc.

Notices


Reply
  Search this Thread
Old 03-05-2014, 12:58 PM   #1
jnojr
Member
 
Registered: Sep 2007
Location: Chandler, AZ
Posts: 227

Rep: Reputation: 20
pf - question on rule matching


I'm getting some logs like:

Code:
00:00:31.119351 rule 2/8(ip-option): pass in on en0: 172.24.32.41 > 224.0.0.1: igmp query v2
Rule 2 is:

Code:
@2 pass in all flags S/SA keep state
I cannot begin to imagine how that rule allowed that packet.

And what's the "/8" in "rule 2/8"?
 
Old 03-08-2014, 01:55 AM   #2
kooru
Senior Member
 
Registered: Sep 2012
Posts: 1,385

Rep: Reputation: 275Reputation: 275Reputation: 275
Well, I admit it sounds as a strange rule.
Anyway "flags S/SA keep state" should be now the default for pass rules in pf.conf
 
Old 03-09-2014, 12:14 PM   #3
jnojr
Member
 
Registered: Sep 2007
Location: Chandler, AZ
Posts: 227

Original Poster
Rep: Reputation: 20
It appears that there's an implicit "pass in all flags S/SA" in pf. Simply commenting out that rule got what I wanted.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Iptables: icmp and fragmented icmp rule matching Cenobite Linux - Networking 2 02-03-2011 03:37 AM
Noob question about matching texts teranom Linux - Newbie 2 03-04-2009 08:42 AM
pattern matching question laopi Linux - General 6 11-05-2008 11:34 AM
pattern matching question - grep cbriscoejr Programming 1 02-09-2006 08:30 PM
Perl Pattern Matching Question pete1234 Programming 2 08-27-2005 10:26 AM

LinuxQuestions.org > Forums > Other *NIX Forums > *BSD

All times are GMT -5. The time now is 12:40 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration