On Sun, Oct 28, 2001 at 02:22:34PM -0800, eliab wrote:

> i can route to any addy as long as pf is disabled, but as soon as i bring
> it up, using pfctl -e, i get 'no route to host' when i ping anything, or
> try to ssh to any hosts.
> how can i figure out what to pass through, if anything?

Add the 'log' option to all blocking rules (you already have that,
mostly), then check /var/log/pflog for entries (tcpdump -n -e -ttt -r
/var/log/pflog as per pflogd(8)). You'll see what packets are block by
what rules.

> block out log quick on $ext_if from ! to any

This blocks all packets from going out if they don't have a source
address of Is that what you want?


