Re: PF packets being blocked...why?

2017-06-27 Thread Marko Cupać
On Mon, 26 Jun 2017 10:02:00 -0600 Steve Williams wrote: > Hi, > > New install of OpenBSD 6.1 on apu2. Love the little box. > > I have em0 as the connection to the Internet and I bridged em1 and > em2 together on 192.168.123.0. > > I've been using OpenBSD since the 2.7 days, but have never ru

Re: PF packets being blocked...why?

2017-06-27 Thread Sterling Archer
On Tue, Jun 27, 2017 at 11:50 AM, Stuart Henderson wrote: > On 2017-06-26, Steve Williams wrote: >> Hi, >> >> New install of OpenBSD 6.1 on apu2. Love the little box. >> >> I have em0 as the connection to the Internet and I bridged em1 and em2 >> together on 192.168.123.0. >> >> I've been using

Re: PF packets being blocked...why?

2017-06-27 Thread Stuart Henderson
On 2017-06-26, Steve Williams wrote: > Hi, > > New install of OpenBSD 6.1 on apu2. Love the little box. > > I have em0 as the connection to the Internet and I bridged em1 and em2 > together on 192.168.123.0. > > I've been using OpenBSD since the 2.7 days, but have never run NAT so > this is my

Re: PF packets being blocked...why?

2017-06-26 Thread Steve Williams
Hi, Yes, I have (what appears to be) 100% functionality of the forwarding/nat/etc. That wouldn't work if forwarding wasn't enabled. # cat /etc/sysctl.conf net.inet.ip.forwarding=1 And I have rebooted multiple times. Thanks, Steve W. On 26/06/2017 12:30 PM, Timo Myyrä wrote: Hmm, have you

Re: PF packets being blocked...why?

2017-06-26 Thread Timo Myyrä
Hmm, have you enabled net.inet.ip.forwarding? Timo Steve Williams writes: > Hi, > > Packets from vether are going out NAT'd no problem. I have 100% > Internet access on 192.168.123.0/24. > > From my understanding, the "pass out quick inet all flags S/SA" allow > packets out and should create s

Re: PF packets being blocked...why?

2017-06-26 Thread Ville Valkonen
Hi, yes, scratch my original message. Shouldn't reply while on the move. -- Ville On Jun 26, 2017 9:14 PM, "Steve Williams" wrote: Hi, Packets from vether are going out NAT'd no problem. I have 100% Internet access on 192.168.123.0/24. >From my understanding, the "pass out quick inet all f

Re: PF packets being blocked...why?

2017-06-26 Thread Steve Williams
Hi, Packets from vether are going out NAT'd no problem. I have 100% Internet access on 192.168.123.0/24. From my understanding, the "pass out quick inet all flags S/SA" allow packets out and should create state for the connection for any ipv4 packets on any interface. Subsequent packets (

Re: PF packets being blocked...why?

2017-06-26 Thread Ville Valkonen
Hello, a quick glance and it seems you aren't allowing vether traffic to pass. -- Regards, Ville On Jun 26, 2017 8:19 PM, "Steve Williams" wrote: > Hi, > > New install of OpenBSD 6.1 on apu2. Love the little box. > > I have em0 as the connection to the Internet and I bridged em1 and em2 > tog

PF packets being blocked...why?

2017-06-26 Thread Steve Williams
Hi, New install of OpenBSD 6.1 on apu2. Love the little box. I have em0 as the connection to the Internet and I bridged em1 and em2 together on 192.168.123.0. I've been using OpenBSD since the 2.7 days, but have never run NAT so this is my first foray into that world. I have followed the F