[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: strange results with pf



Matthijs Mohlmann wrote:

>If i'm right:
>
>block return-rst in inet proto tcp all
>
this rule is in my pf.conf (see the previous letter)

>
>You don't close the tcp connection at all and then nmap says it's a open
>port.
>
The talk is about all protocols (not only tcp) and protocol scanning by
nmap.
If I have single rule such this "pass all" in pf.conf - my host sends
icmp "proto-unr" but
with the given configuration does not!!!

>
>I'm not sure but i think that rule it is.
>


-- 
Alexei Malinin,
Chief Specialist of
Network Technologies Department,
ECom-IT Limited,  Moscow
Basic Element Inc.,  Russia