Re: pf and traceroute

2011-01-17 Thread Indunil Jayasooriya
Hi, I am on a 64 bit OpenBSD 4.8 stable. Here is mine on OpenBSD 4.8 firewall/router # both traceroute www.google.lk and traceroute -I www.google.lk work. From my fedora client, traceroute www.google.lk works. and traceroute -I www.google.lk also works. But second hope gives in this way

Re: pf and traceroute

2011-01-17 Thread Johan Fredin
On 16 jan 2011, at 18:49, Mike. wrote: In any case, now that I've moved to OpenBSD 4.8 for the firewall/router everything is working as expected now. I can traceroute from the FreeBSD client, and Windows without a problem. This was fixed between 4.7 and 4.8:

Re: pf and traceroute

2011-01-16 Thread Mike.
On 1/15/2011 at 8:00 AM David Walker wrote: Hi David, |[snip] | |What OS are we talking about now? I had been running OpenBSD 4.7 GENERIC#558 i386 Yesterday I installed (not upgraded, but a fresh install) OpenBSD 4.8 GENERIC#136 i386 and the ICMP traceroutes now work as expected. The

Re: pf and traceroute

2011-01-14 Thread Mike.
On 1/13/2011 at 5:59 AM David Walker wrote: |Hi Mike. | |[snip] | |Second, and here we go into grey area, I'm no expert at the pf thing |and I do it slightly different to you. |However, I use a simple ruleset and don't explicitly allow ICMP ... |and yet it works from internal Windows and OpenBSD

Re: pf and traceroute

2011-01-14 Thread David Walker
Hi Mike. Mike wrote: Yes, I know that Windows uses ICMP for traceroute (I use both the Windows tracert command line utility and the SamSpade GUI utility). Cool. However, I have found that troubleshooting is always easier if one can eliminate Windows from the mix, that's why I reproduced the

Re: pf and traceroute

2011-01-13 Thread Mike.
On 1/13/2011 at 5:59 AM David Walker wrote: |Hi Mike. | |Here's a couple of points. | |First, Windows uses ICMP only on traceroute (tracert) so there's |consistency between your Windows and FreeBSD internal hosts - it's an |ICMP blocked (in or out) issue. |

Re: pf and traceroute

2011-01-12 Thread David Walker
Hi Mike. Here's a couple of points. First, Windows uses ICMP only on traceroute (tracert) so there's consistency between your Windows and FreeBSD internal hosts - it's an ICMP blocked (in or out) issue. http://technet.microsoft.com/en-us/library/cc940128.aspx Can you ping and traceroute your

pf and traceroute

2011-01-11 Thread Mike.
I'm having difficulty getting traceroute to work on some of the network clients (Windows, specifically). I've been able to reproduce the problem, and I've documented it below. Any assistance and/or guidance on the error (of omission or comission) in my pf.conf file would be appreciated. (I