Re: DF flag with af-to rule

2013-07-06 Thread Pawel Jurusz
Hello Marios DF bit shouldn't be cleared, because it's necessary for PMTUD (Path MTU Discovery). There is also nothing amazing, that packets has DF flag set (it depends on operating system) Hello misc@, I currently have a VM running as a NAT64 gateway. It is running OpenBSD 5.3 with the vio

Re: pf and apache

2013-03-01 Thread Pawel Jurusz
Hello, If You are using only redirections, source host will receive SYN-ACK from 192.168.1.70, but there was not previously SYN to this address, so source host will send TCP Reset. Solution may be: pass in on $int_if proto tcp from $int_if:network to any port 80 rdr-to 192.168.1.70 pass out on