[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: PF: passing via port { protocol }



On Tue, Oct 16, 2001 at 03:30:12PM +0000, karlski wrote:
> howdy, i'm testing pf.conf rules on a 3.0 transparent firewall (bridge
> mode)...  just wanting to pass IPSEC traffic via a line similar to:
> 
> pass in on le1 inet proto tcp from any to any port { ipsec }
> pass out on le1 inet proto tcp from any to any port { ipsec }

wrong 

See the FAQ 13.11 second point.

> 
> Question: In reading man pf.conf i'm looking for a list of allowable
> protocols?  How would I specify PPTP, or SFTP, or ESP/AH (IPSEC) in the
> brackets?  

In most place you can use either a name or a number.

for "proto" see /etc/protocols
for "port" see /etc/services

if you can find what you want, just put the number. 

"port" can only be use with udp, tcp.

Yes, (pptp[gre], esp, ah) are IP protocols but they [optionaly in
some case] also use tcp or udp to negociate state/options/etc.


Hugo Villeneuve