ieee
ieee
Hi! Kann z. Zt. mit fetch und ftp keine Dateien von ftp://ftp.gnu.org/ holen, die Verbindung wird nach wenigen Sekunden immer langsamer und bricht dann schließlich ganz zusammen. Browsen mit Firefox geht ohne Probleme, auch Downloads laufen komplett und mit normaler Geschwindigkeit durch. pfctl gibt bei mir folgende Regeln aus:
Wenn ich die Regeln lösche und alles erlaube, läuft's wieder normal, also muss es definitiv an den Regeln liegen. Ich lasse z. B. kein icmp und udp rein - ist das notwendig für ftp?
Code:
nat on tun0 inet from 10.255.255.160/29 to any -> (tun0) round-robin
rdr on tun0 inet proto tcp from ! 10.255.255.166 to ! 10.255.255.160/29 port = ftp -> 127.0.0.1 port 8021
rdr on sis0 inet proto tcp from any to any port = http -> 127.0.0.1 port 3128
scrub in all fragment reassemble
block drop log all
pass on lo0 all
pass on sis0 all
block drop in log quick on tun0 inet proto tcp all flags FPU/FPU
block drop in log quick on tun0 inet proto tcp all flags FS/FSRA
block drop in log quick on tun0 inet proto tcp all flags /FSRA
block drop in log quick on tun0 inet proto tcp all flags FS/FS
block drop in quick on tun0 from <rfc1597> to any
block drop out quick on tun0 from any to <rfc1597>
block drop in quick on tun0 inet proto udp all
block return-icmp(port-unr, port-unr) in on tun0 all
pass out on tun0 inet proto icmp all icmp-type echorep keep state
pass out on tun0 inet proto icmp all icmp-type echoreq keep state
pass out on tun0 inet proto icmp all icmp-type timex keep state
pass out on tun0 proto udp from any to any port = domain keep state
pass out on tun0 proto tcp from any to any port = ftp flags S/SA modulate state
pass out on tun0 proto tcp from any to any port = ssh flags S/SA modulate state
pass out on tun0 proto tcp from any to any port = smtp flags S/SA modulate state
pass out on tun0 proto tcp from any to any port = http flags S/SA modulate state
pass out on tun0 proto tcp from any to any port = pop3 flags S/SA modulate state
pass out on tun0 proto tcp from any to any port = auth flags S/SA modulate state
pass out on tun0 proto tcp from any to any port = locus-map flags S/SA modulate state
pass out on tun0 proto tcp from any to any port = https flags S/SA modulate state
pass out on tun0 proto tcp from any to any port = smtps flags S/SA modulate state
pass out on tun0 proto tcp from any to any port = imaps flags S/SA modulate state
pass out on tun0 proto tcp from any to any port = pop3s flags S/SA modulate state
pass out on tun0 proto tcp from any to any port = cvsup flags S/SA modulate state
pass out on tun0 proto tcp from any to any port 8080:65535 flags S/SA modulate state
pass in on tun0 proto tcp from any to any port 49152:65535 flags S/SA modulate state