[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: strange results with pf
Matthijs Mohlmann wrote:
>If i'm right:
>
>block return-rst in inet proto tcp all
>
this rule is in my pf.conf (see the previous letter)
>
>You don't close the tcp connection at all and then nmap says it's a open
>port.
>
The talk is about all protocols (not only tcp) and protocol scanning by
nmap.
If I have single rule such this "pass all" in pf.conf - my host sends
icmp "proto-unr" but
with the given configuration does not!!!
>
>I'm not sure but i think that rule it is.
>
--
Alexei Malinin,
Chief Specialist of
Network Technologies Department,
ECom-IT Limited, Moscow
Basic Element Inc., Russia