Re: pf rdr-to and access from internal network

2014-10-31 Thread Julian Smith
Thanks for the various responses, and especially to trondd for lots of email help, which enabled me to fix the problem. The problem was caused by two faults in my setup, which i thought i'd describe here, in case anyone else has similar problems. The main problem was that my /etc/hosts (and so

Re: pf rdr-to and access from internal network

2014-10-29 Thread Blaise Hizded
On 10/28/2014 07:57 PM, Julian Smith wrote: On Tue, 28 Oct 2014 13:40:52 -0400 trondd tro...@gmail.com wrote: Are you telnetting to the external IP of the server from the internal client? Yes. Actually i've tried using the external IP and the internal IP. Both have the same result - telnet

Re: pf rdr-to and access from internal network

2014-10-29 Thread Stuart Henderson
On 2014-10-28, Julian Smith ju...@op59.net wrote: Yes, i've enabled logging and i see various items such as: ju...@server-55.my.domain:~ sudo tcpdump -v -i pflog0 Add -e to the tcpdump line, it will show you action (block/match/pass) and rule numbers, then check the traffic hits the expected

Re: pf rdr-to and access from internal network

2014-10-28 Thread Julian Smith
On 27 Oct 2014 21:29:07 +0100 pe...@bsdly.net (Peter N. M. Hansteen) wrote: Julian Smith ju...@op59.net writes: pass in on $int_if proto tcp from $int_net to $ext_if port 80 rdr-to $server pass out on $int_if proto tcp to $server port 80 received-on $int_if nat-to $int_if

Re: pf rdr-to and access from internal network

2014-10-28 Thread trondd
Are you telnetting to the external IP of the server from the internal client? Have you enabled logging in pf? Are the packets blocked or are they passed by a different rule that doesn't give the expected results? Tim.

Re: pf rdr-to and access from internal network

2014-10-28 Thread Julian Smith
On Tue, 28 Oct 2014 13:40:52 -0400 trondd tro...@gmail.com wrote: Are you telnetting to the external IP of the server from the internal client? Yes. Actually i've tried using the external IP and the internal IP. Both have the same result - telnet says 'telnet: Unable to connect to remote host:

Re: pf rdr-to and access from internal network

2014-10-27 Thread Peter N. M. Hansteen
Julian Smith ju...@op59.net writes: pass in on $int_if proto tcp from $int_net to $ext_if port 80 rdr-to $server pass out on $int_if proto tcp to $server port 80 received-on $int_if nat-to $int_if First question - what is '$int_net' ? I can't find it defined in the pf.conf man