Re: What stupid mitake am I making?

2009-12-22 Thread stan
On Tue, Dec 22, 2009 at 12:51:11PM -0500, Steve Shockley wrote: On 12/22/2009 11:35 AM, stan wrote: int_if = eme0 ? OK now I have this: set skip on lo ext_if = bge0 int_if = em0 pfsync_if = em1 match in all scrub (no-df) block out quick from $pfsync_if to $ext_if block out quick from

Re: What stupid mitake am I making?

2009-12-22 Thread Jussi Peltola
State. Blocking outgoing traffic will not prevent replies being allowed out.

Re: What stupid mitake am I making?

2009-12-22 Thread stan
On Tue, Dec 22, 2009 at 10:18:11PM +0200, Jussi Peltola wrote: State. Blocking outgoing traffic will not prevent replies being allowed out. OK, but pfctl -s rules includes the following:' block drop in quick inet from any to 192.168.254.0/24 Which I think is an expansion of this rule I have

Re: What stupid mitake am I making?

2009-12-22 Thread Aaron Mason
On Wed, Dec 23, 2009 at 6:51 AM, stan st...@panix.com wrote: On Tue, Dec 22, 2009 at 12:51:11PM -0500, Steve Shockley wrote: On 12/22/2009 11:35 AM, stan wrote: int_if = eme0 ? OK now I have this: set skip on lo ext_if = bge0 int_if = em0 pfsync_if = em1 match in all scrub (no-df)