{"id":955,"date":"2017-04-27T22:16:35","date_gmt":"2017-04-28T02:16:35","guid":{"rendered":"http:\/\/www.rfdm.com\/blog\/?p=955"},"modified":"2017-04-27T22:49:50","modified_gmt":"2017-04-28T02:49:50","slug":"mcblockds-next-tricks-kill-pf-state-walk-pcb-list-and-kill-tcp-connections","status":"publish","type":"post","link":"https:\/\/www.rfdm.com\/blog\/?p=955","title":{"rendered":"mcblockd&#8217;s latest tricks: kill pf state, walk PCB list and kill TCP connections"},"content":{"rendered":"<p>Today I added a new feature to mcblockd to kill pf state for all hosts in a prefix when the prefix is added to one of my pf tables.  This isn&#8217;t exactly what I want, but it&#8217;ll do for now.<\/p>\n<p>mcblockd also now walks the PCB (protocol control block) list and drops TCP connections for hosts in a prefix I&#8217;ve just added to a pf table.  Fortunately there was sample code in <tt>\/usr\/src\/usr.sbin\/tcpdrop\/tcpdrop.c<\/tt>.  The trick here is that I don&#8217;t currently have a means of mapping a pf table to where it&#8217;s applied (which ports, which interfaces).  In the long term I might add code to figure that out, but in the interim I can configure ports and interfaces in mcblockd&#8217;s configuration file that will allow me to drop specific connections.  For this first pass, I just toast all PCBs for a prefix.<\/p>\n<p>The reason I added this feature: I occasionally see simultaneous login attempts from different IP addresses in the same prefix.  If I&#8217;m going to block the prefix automatically, I want to cut off all of their connections right now, not after all of their connections have ended.  Blowing away their pf state works, but leaves a hanging TCP connection in the ESTABLISHED state for a while.  I want the PCBs to be cleaned up.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today I added a new feature to mcblockd to kill pf state for all hosts in a prefix when the prefix is added to one of my pf tables. This isn&#8217;t exactly what I want, but it&#8217;ll do for now. mcblockd also now walks the PCB (protocol control block) list and drops TCP connections for &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.rfdm.com\/blog\/?p=955\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;mcblockd&#8217;s latest tricks: kill pf state, walk PCB list and kill TCP connections&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[29,85,12],"tags":[],"class_list":["post-955","post","type-post","status-publish","format-standard","hentry","category-freebsd","category-network-security","category-software-development"],"_links":{"self":[{"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/955","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=955"}],"version-history":[{"count":8,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/955\/revisions"}],"predecessor-version":[{"id":965,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/955\/revisions\/965"}],"wp:attachment":[{"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=955"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=955"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rfdm.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=955"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}