Re: Odd PF Denied Message

2007-10-19 Thread Ian Smith
On Fri, 19 Oct 2007, Nikos Vassiliadis wrote: > On Friday 19 October 2007 07:06:35 Ian Smith wrote: > > On Thu, 18 Oct 2007 19:36:27 +0300 Nikos Vassiliadis wrote: .. > > > I think log_in_vain can be used when configuring a firewall. > > > Just to see quickly if your firewall works as expect

Re: Odd PF Denied Message

2007-10-19 Thread Nikos Vassiliadis
On Friday 19 October 2007 07:06:35 Ian Smith wrote: > On Thu, 18 Oct 2007 19:36:27 +0300 Nikos Vassiliadis wrote: > > If that's the only message you get > > you must be protected, at least packet_filtering-wise. Here > > I think log_in_vain can be used when configuring a firewall. > > Ju

Re: Odd PF Denied Message

2007-10-18 Thread Ian Smith
On Thu, 18 Oct 2007 19:36:27 +0300 Nikos Vassiliadis wrote: > On Thursday 18 October 2007 18:39:56 Michael K. Smith - Adhost wrote: > > Thank you for the clue! We are using log in vain as part of our > > security logging for this particular box, but this is the only message > > I've ever seen

Re: Odd PF Denied Message

2007-10-18 Thread Peter N. M. Hansteen
"Michael K. Smith - Adhost" <[EMAIL PROTECTED]> writes: > We've basically allowed all traffic to and from 127.0.0.1 in our > ruleset, but nothing seems to work. Does anyone have a magic bullet to > make this go away? set skip on lo0 is not the default, but essentially the only sane way to go. Se

Re: Odd PF Denied Message

2007-10-18 Thread Nikos Vassiliadis
On Thursday 18 October 2007 18:39:56 Michael K. Smith - Adhost wrote: > Thank you for the clue! We are using log in vain as part of our > security logging for this particular box, but this is the only message > I've ever seen so I'm not sure it's really needed. It must be a local program trying t

RE: Odd PF Denied Message

2007-10-18 Thread Michael K. Smith - Adhost
Hello Nikos: > -Original Message- > From: Nikos Vassiliadis [mailto:[EMAIL PROTECTED] > Sent: Thursday, October 18, 2007 9:30 AM > To: freebsd-questions@freebsd.org > Cc: Michael K. Smith - Adhost > Subject: Re: Odd PF Denied Message > > On Thursday 18 October

Re: Odd PF Denied Message

2007-10-18 Thread Nikos Vassiliadis
On Thursday 18 October 2007 17:59:49 Michael K. Smith - Adhost wrote: > Hello All: > > We're getting a ton of these. > > +Connection attempt to TCP 127.0.0.1:113 from 127.0.0.1:52655 flags:0x02 This doesn't look like a pf(4) message. This looks like sysctl net.inet.tcp.log_in_vain is 1. It logs ev