Web Images Videos Maps News Groups Gmail more »
Recently Visited Groups | Help | Sign in
Google Groups Home
reply-to help, icmp host unreachable
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  1 message - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
gmcconkey@gmail.com  
View profile  
 More options Aug 9, 2:12 pm
Newsgroups: bit.listserv.openbsd-pf
From: "gmccon...@gmail.com" <gmccon...@gmail.com>
Date: Sat, 8 Aug 2009 21:12:37 -0700 (PDT)
Local: Sun, Aug 9 2009 2:12 pm
Subject: reply-to help, icmp host unreachable
Been staring at this too long, maybe another pair of eyes can help
out.

Bascially trying to bring up another internet connection, 3rd one, and
want to provide some internet accessible services via the non primary
connection.  All connections are handed off to me as straight ethernet
with static IP's, no pppoe or the like.  Things work fine off the
primary conneciton, the second one I just use for web surfing traffic
(nothing coming in from it), and this 3rd one will replace the primary
after a while.

$Greg_ip is a host on the internet I use for testing from outside.

isp3EXTwebserver_ip = "internetip/32"
DMZwebserver = "dmzip/32"
nat on $isp3_if from $DMZwebserver to any -> $isp3EXTwebserver_ip
nat on $isp1_if from $DMZwebserver to any -> $EXTwebserver
rdr on $isp3_if proto tcp from $greg_ip to $isp3EXTwebserver_ip port
https -> $DMZwebserver port https

pass in quick on $isp3inet_if reply-to ($isp3_if $isp3_gw) proto tcp
from $greg_ip to $DMZwebserver port https keep state
#pass out quick on $dmz_if from any to any
#pass in quick on $dmz_if from any to any
pass out quick on $dmz_if from any to $DMZwebserver keep state
pass in quick on $dmz_if from any to any keep state
pass out quick on $isp3inet_if from any to $greg_ip

Using tcpdump
Request comes in Via isp3 interface
Passed out the DMZ interface to the server
Server replies on DMZ interface, and that's it never makes it back out
any other interface.
I then see on the DMZ interface a icmp host unreachable sent to the
web server.  Block-policy is set to drop.  What else can I do to see
why it is sending the icmp host unreachable and the reply not making
it back to the internet?

I moved the rules to the top and put quicks on them so they are the
first rules evaluated.  Running OpenBSD 4.5 stable, all patched up.  I
also put a route-to for surfing and my machine behind it can surf the
internet send pings out other traffic through the isp3 interface just
fine.

Thanks,
Greg


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2009 Google