Re: pf.conf newbie help

From: Dave Uhring (daveuhring_at_yahoo.com)
Date: 08/25/04

  • Next message: Adam Mitchell: "Memory protection, W^X, guard pages, etc."
    Date: Tue, 24 Aug 2004 21:19:51 -0500
    
    

    On Tue, 24 Aug 2004 18:32:16 -0700, Dennis Russo wrote:

    > I am sure the nameserver is working.

    How are you sure? Does its /etc/resolv.conf look like this?

    [root]# cat /etc/resolv.conf
    lookup file bind
    nameserver 127.0.0.1

    If you are in an ssh session to the server does it resolve openbsd.org?

    [root]# host openbsd.org
    openbsd.org has address 199.185.137.3

    > When I comment out everything
    > except the nat and add pass in all/pass out all rules, it works great
    > (both for computers accessing the web from behind the obsd box and
    > computers trying to access from the internet). I don't want to
    > firewall packets from my LAN, I want to firewall packets to my LAN.

    You should not have any 'pass in' or 'pass out' rules with $IntIF as one
    of the arguments to the rules, except for:

    pass in on $IntIF all
    pass out on $IntIF all


  • Next message: Adam Mitchell: "Memory protection, W^X, guard pages, etc."

    Relevant Pages

    • Re: Help with long term network problem
      ... DATA by other machines on the LAN. ... Depending on the boot sequence of the computers this changed. ... dispensing with the dedicated server and just using on as file ...
      (microsoft.public.windowsxp.network_web)
    • Re: Linux Server, Please Help
      ... and squid with adzapper set up to be a transparent proxy. ... On the LAN is a network printer, and other computers running, ... outgoing mail and wait for a connection before sending to the ...
      (Debian-User)
    • Re: non domain computers on network
      ... I need the security reasons spelled out - links are fine I ... new computer and bring thier PC with them and plug into the LAN. ... computers on their separate VLAN, and have then connected to the printers ... (assuming these are network printers). ...
      (microsoft.public.windows.server.networking)
    • Re: Browsing WIndows Network "broken" with Symantec VPN/100 firewall appliance
      ... >Nothing in the Symantec KB mentions LAN Browsing except a small blurb ... >properly" and to "verify that all computers are on the same Workgroup ... >Special Application tweak do I? ... Lars M. Hansen ...
      (comp.security.firewalls)
    • Re: Windows XP Pro security question
      ... I have inherited a small business LAN of 7 computers running Win XP Pro /SP2 ... is there any way 'reset' the file system permissions back to the ...
      (microsoft.public.windowsxp.general)