Re: RST packets not being natted or unmapped through rdr

2006-04-02 Thread Jon Hart
On Sat, Apr 01, 2006 at 05:01:11AM -0600, Travis H. wrote: Aside: What combinations of TCP flags does scrub filter out? From my understanding and a re-reading of pf.conf(5), scrub does no filtering of TCP at all unless you use the 'reassemble tcp' option. Even when it is on, the man page does

RST packets not being natted or unmapped through rdr

2006-04-01 Thread Travis H.
Hi, I was examining my WAN connection the other day, and I found something strange. I have rdr and nat rules in place for this connection; some ports are forwarded to an internal host; and nat occurs for everything going out. However, I noticed that RST packets coming from the internal host