Does PF firewall have stateless rules

From: fbsd_user (fbsd_user_at_a1poweruser.com)
Date: 07/07/05

  • Next message: Jud: "Re: How do I reinstall the FreeBSD bootmanager? - next problem :-("
    To: "freebsd-questions@FreeBSD. ORG" <freebsd-questions@FreeBSD.ORG>
    Date: Wed, 6 Jul 2005 21:34:53 -0400
    
    

    Does the OpenBSD Packet Filter firewall have stateless rules?
    Meaning, if I coded a rule to pass in for port 23 without any of the
    different state options coded,
    do I also have to code the same kind of rule to allow that port 23 packet
    back out like in IPFW.

    Or is there no stateless rules in PF?
    Meaning that coding a rule to pass in for port 23 without any of the
    different state options coded,
    it defaults to standard state processing and the resulting outbound packet
    will be allowed out
    because it belongs to the same session.
    _______________________________________________
    freebsd-questions@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-questions
    To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org"


  • Next message: Jud: "Re: How do I reinstall the FreeBSD bootmanager? - next problem :-("

    Relevant Pages

    • PATCH: Remove file riowinif.h from rio driver (unused file)
      ... -/* The RUP (Remote Unit Port) structure relates to the Remote Terminal Adapters ... - CONFIG is sent from the driver to configure an already opened port. ... - Packet structure is same as OPEN. ... - of the specified port's RTA address space. ...
      (Linux-Kernel)
    • Re: General questions about Sockets
      ... > could I push it before I see the network slowing down and/or errors? ... Nagle/Delayed ACK interaction but you could confirm it with a packet ... > I can setup any port in my registry, but what would be the 'default' one I ... Google could confirm it. ...
      (microsoft.public.win32.programmer.networks)
    • RE: Strange replies on closed port
      ... port should be a RST - not dropping the packet. ... receiving an UDP datagram to a non 'listening' port. ... that message isn't generated by the end host, ... Connecting to a closed Port w/o Firewall: ...
      (Pen-Test)
    • Re: Please help me interpret a suspicious netstat SYN_SENT TCP port 1058 ?
      ... Your system initiated a connection. ... your computer sends a TCP packet with the SYN ... Process 912 on your system sent a packet from port 1058 ... hoping to connect to the web server running on port 80 ...
      (comp.security.firewalls)
    • Re: Full Plate of Crow
      ... upsurges in port 80 probes and actually ... > firewall is only telling it dropped a packet, not what was in the packet. ... infections based on the data Caida collected. ... > firewall logs, not IDS logs. ...
      (Incidents)