[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: 3.1 pf question



On Mon, Jul 08, 2002 at 06:01:54PM -0400, coldiso_(_at_)_houx_(_dot_)_org wrote:
> My issue:
> 
>         I want to forward port say 3022 to another machine behind the 
> firewall to port 22.  This is my config pf and nat respectivley.
> 
> <pf_snip>
> pass in log on $ext_if inet proto tcp from any to any port = 3022 flags S/SA
> </pf_snip>
> 
> <nat_snip>
> rdr on $ext_if proto tcp from any to any port 3022 -> 192.168.1.191 port 22 
> </nat_snip>
> 
> Where the oddness happens is I can't conect to port 3022 unless I add this 
> statement to pf.conf
> 
> pass in log quick on $ext_if inet proto tcp from any to any port = 22 flags S/SA

yes. rdr happens BEFORE the filter rules see the traffic.