tech-net archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: pf synproxy doesn't pass to local services



I've repeated my tests on -current/macppc and it behaves the same way.

If a pf rule allowing access to a local service (such as SSH) uses
"synproxy state", the TCP handshake is proxied with the client, but
the connection is apparently not passed to the daemon, (such as 'sshd').

If the rule uses "modulate state" or just "keep state", the connection
to the service succeeds.

It the rule allows access to a service through a connection redirected
to another host, "synproxy state" works fine.

--
John D. Baker, KN5UKS                    NetBSD     Darwin/MacOS X
jdbaker(at)mylinuxisp(dot)com                 OpenBSD            FreeBSD
BSD -- It just sits there and _works_!
GPG fingerprint:  D703 4A7E 479F 63F8 D3F4  BD99 9572 8F23 E4AD 1645



Home | Main Index | Thread Index | Old Index