Re: PF and states of connections with same src port

2008-05-04 Thread Jordi Espasa Clofent
It's related to timeout options. man pf.conf(5), Options sections, timeouts. By default, pf offers to you a three 'lists' of timeouts values: Conservative, Normal and Aggressive. If you want to drop completely the connections states early, you can use Aggressive staff. But PF is extremely

PF and states of connections with same src port

2008-05-02 Thread B A
Hello! I have question about PF. I have just found interesting behavior of of PF. For example if I fix source port and run from my PC: echo 'aaa' | nc -p www.my.rerver 80 I got response. But if I just run this command again - connection stuck. I should wait about 1 min to be

Re: PF and states of connections with same src port

2008-05-02 Thread Kian Mohageri
On Fri, May 2, 2008 at 7:35 AM, B A [EMAIL PROTECTED] wrote: Hello! I have question about PF. I have just found interesting behavior of of PF. For example if I fix source port and run from my PC: echo 'aaa' | nc -p www.my.rerver 80 I got response. But if I just

Re: PF and states of connections with same src port

2008-05-02 Thread B A
I found this notes http://www.openbsd.org/cgi-bin/cvsweb/src/sys/net/pf.c?rev=1.559content-type=text/x-cvsweb-markup Will try upgrade (I'm running 4.1) and see 02.05.08, 20:21, Kian Mohageri [EMAIL PROTECTED]: States aren't purged immediately. Take a look at the timeout values,