Lasse Stig Thomsen wrote:

Also i can get fx irssi  to run from the openBSD box, if i have set
those rules, even if i set "pass out quick log on $ext_if all" irssi
wont get connected. I have to open for all incoming traffic to get it
online. Even lynx wont connect to anything, what point of packetfilter
am i missing. (i have read the FAQ numerus times.)

In the ruleset above, you have no rule that passes traffic out on $ext_if from the OpenBSD box; you're only passing from the internal LAN. In the rule you said you tried above, you're missing "keep state".




.joel



Reply via email to