[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

strange things with stateful tracking



Hello, misc.
i see some strange things using stateful tracking in openbsd3.6
with such rule in pf.conf:
pass in on $ext_if proto tcp from any to ($ext_if) port 21\
     flags S/SA keep state
pass in on $ext_if proto tcp from any to ($ext_if) port >49151\
     flags S/SA keep state ( source-track rule, max-src-states 3 )

clients stucks getting list of directory (`w` says
ftp    ft 10.0.0.243       12:07PM     0 PASV),
but when i try to <refresh> few times (3 or more) they get it.
without "( source-track rule, max-src-states 3 )" everything's ok
what could be wrong? or should i try to use current?

-- 
Best wishes,
 Serge                          mailto:serge_(_at_)_betatk_(_dot_)_ru



Visit your host, monkey.org