Re: Still can't use ADSL, PF problem

From: clvrmnky (clvrmnky-uunet_at_coldmail.com.invalid)
Date: 08/23/04


Date: Mon, 23 Aug 2004 13:34:14 -0400

On 23/08/2004 12:05 AM, Johnathan Doe wrote:

> I wasn't working as root. I used sudo to do edit the configuration files
> with vi. I added my user account to the network and dialers groups, as
> well as wheel. So there was no reason for me to suspect that I needed to
> be root.
>
I'm not sure what your exact problem is that was caused by tweaking PF
as a non-privileged user, but PF talks to the network devices via some
privileged devices. I've found that using sudo when running any pfctl
command is necessary to do anything. The rulesets should just work when
reapplied. No reboot is necessary.

> There are yet more problems, too. Nothing but google works. Absolutely
> nothing! Can't even get the OpenBSD website. I can ftp to openbsd
> (sunsite in Canada) but then it freezes up, without fail, after a couple of
> directory changes. Same with every other ftp connection.
>
Use a PASV connection. The DIR commands will cause apparent lockups on
(some) firewalled connections unless the ftp client is setup to connect
passively. I'm hand-waving here, I know, but the FTP issue may be
unrelated to anything else you are experiencing. Google for the details.

> Jeez, I can't believe how impossibly difficult it is to use OpenBSD for
> simple everyday tasks!
>
The admins here at work have all been heard to say the exact opposite.
My own users have heard me exclaim how hard OpenBSD "rocks" while
tweaking the edge box running OpenBSD.

I second the advice to look at the FAQ examples and build your ruleset
up from there. The examples reflect real-world use.



Relevant Pages

  • rdr with pf and proxying (newbie question)
    ... this is how my network is arranged: ... I have the following interfaces on OpenBSD: ... dc0 (connection between OpenBSD and Linksys router) IP is 192.168.1.1 ... I have internet on the OpenBSD box. ...
    (comp.unix.bsd.openbsd.misc)
  • Re: Connection Aborted Message on IIS6 FTP
    ... it look like the interface itself is having issue. ... I can't find much info on this error, so you may need to ping your network ... you mentioned sometime no ftp connections can be made at all, ... still in between proxy/firewall/router acl/etc might prevent the connection ...
    (microsoft.public.inetserver.iis.ftp)
  • FTP server publishing
    ... perimeter network on the back firewall. ... FTP on the same server as the web sites are published. ... fine before the introduction of ISA. ... connection ...
    (microsoft.public.isa.enterprise)
  • Re: Cant obtain 4.11 ?
    ... > or to have the server initiate a separate data connection. ... > latter often breaks on firewalls that don't explicitly support ftp. ... > Your network link alone does not comprise the entire network of inter- ... the Finder FTP is always noticeably slower to ANY server. ...
    (comp.unix.bsd.freebsd.misc)
  • Re: Advanced WinINet - Please HELP!
    ... im always connecting to the same ftp server, ... working connection to the internet. ... a network operation takes in a clean way, ...
    (microsoft.public.windowsce.embedded.vc)