On Wed, Mar 30, 2005 at 09:51:07PM -0500, [EMAIL PROTECTED] wrote: > Why are the following packets being blocked? I know that I have flags > S/SA modulate state, and that F or FP do not match S/SA, but does that > matter since its in state?
if you didn't get to solve this yet, is it perhaps a situation where they're being blocked outside the window of when the state was torn down? like, after the first(?) FIN or RST are seen, and the state gets torn down, and then more packets get sent over the wire which are/were part of that connection, but pf has torn it down by that point? i know i'm explaining it poorly; , what if you set optimization to conservative?, if it doesn't happen then, that's what i'm trying to say. jared -- [ openbsd 3.7 GENERIC ( mar 18 ) // i386 ]