Re: pf ruleset parser re: tag and tagged
Sadegh Solati <[email protected]> Wed, 31 Jan 2018 16:42:52 +0100
| Newsgroups | gmane.os.openbsd.pf |
|---|---|
| Message-ID | <CAOH0dtAdVpWBNEbexd+mJP6X+CvNM8apN8oeLqNy2=H0m28rXg@mail.gmail.com> |
--94eb2c057516104a28056414558e Content-Type: text/plain; charset="UTF-8" Actually I think the problem is not with the tag/tagged. It comes from the rule that If it is a quick one or not. When the rule is not quick it won't be matched with the tagged one for updating the tag value.If it is quick it will never see the next rule which is going to check the new tag value. It will be very hard for the parser to fire an accurate alarm in these cases. On Jan 31, 2018 09:01, "S. Donaldson" <[email protected]> wrote: > Hi, > > Ran into a user error situation that perhaps the pf ruleset parser > could help with. > > I was working on rules and using tag/tagged and the rule that > should have 'applied' a tag used 'tagged value' instead of 'tag value'. > Thus the tag was never set and the subsequent 'pass .... tagged value' rule > never fired. > > It seems that tag references are not dynamically defined [ unless > perhaps they are used in authpf scenarios? ]. Would it make sense for the > parser to issue a warning if a 'tagged value' references appear but no > defining 'tag value' is found in a ruleset? > > > Scott Donaldson > Saskatoon, SK > Canada > > --94eb2c057516104a28056414558e Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"auto">Actually I think the problem is not with the tag/tagged. = It comes from the rule that If it is a quick one or not. When the rule is n= ot quick it won't be matched with the tagged one for updating the tag v= alue.If it is quick it will never see the next rule which is going to check= the new tag value. It will be very hard for the parser to fire an accurate= alarm in these cases.</div><div class=3D"gmail_extra"><br><div class=3D"gm= ail_quote">On Jan 31, 2018 09:01, "S. Donaldson" <<a href=3D"m= ailto:[email protected]">[email protected]</a>> wrote:<br ty= pe=3D"attribution"><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 = .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi,<br> <br> =C2=A0 =C2=A0 =C2=A0 =C2=A0 Ran into a user error situation that perhaps th= e pf ruleset parser could help with.<br> <br> =C2=A0 =C2=A0 =C2=A0 =C2=A0 I was working on rules and using tag/tagged and= the rule that should have 'applied' a tag used 'tagged value&#= 39; instead of 'tag value'. Thus the tag was never set and the subs= equent 'pass .... tagged value' rule never fired.<br> <br> =C2=A0 =C2=A0 =C2=A0 =C2=A0 It seems that tag references are not dynamicall= y defined [ unless perhaps they are used in authpf scenarios? ]. Would it m= ake sense for the parser to issue a warning if a 'tagged value' ref= erences appear but no defining 'tag value' is found in a ruleset?<b= r> <br> <br> Scott Donaldson<br> Saskatoon, SK<br> Canada<br> <br> </blockquote></div></div> --94eb2c057516104a28056414558e--