PF and DHCP issues with Mac Mini Server
Hi,
I've been configuring my new Mac Mini server and for the most part things are working as they should but I have a couple problems that I haven't been able to figure out by myself. I'm not a professional in this matter but have some level of knowledge when it comes to running my own home server. My current configuration is as follows:
Setup
Mac Mini (Late 2012) running Mac OS X 10.9.5 (Mavericks) with Server app 3.2.1 acting as a router. Built in ethernet (en0) serving internal network using 10.10.10.0/24 subnet. Thunderbolt to ethernet adapter (en4) connected to external network with static IP. Public DNS hosted by ISP, lookups working properly. Two Airport Extremes configured as a roaming network. Mixed set of clients within the network running Mac OS X, Windows 7, 8, 8.1, iOS, WP8.1
Services
Configured from server app. DNS for internal 10.10.10.0/24 network with ISP DNS servers as forwarders. Also running DHCP, OD, Mail Server, Web Server. NAT and Packet Filter configured using IceFloor.
PF rules
Outbound: All services, all interfaces
Inbound: From 10.10.10.0/24 all services, all interfaces.
From any 53 67 68 123 389 636 5353 5354, all interfaces.
From any 22 25 80 110 143 443 465 587 993 995, all interfaces, tcp.
Options: Multicast DNS allowed, Emerging Threats protection enabled, Stealth mode enabled.
Custom: pass in on en0 inet proto udp from any to 255.255.255.255 keep state
pass in on en0 inet proto udp from any to 10.10.10.255 keep state
Problems
pffirewall.log is flooded with following messages (xxx.xxx.xxx.xxx is my public IP) where the source port is always 993 but the destination varies within the UDP dynamic range.
Sep 26 12:28:21 mydomain.com pf[221]: 00:00:00.000088 rule 12/0(match): block in on en4: xxx.xxx.xxx.xxx.993 > xxx.xxx.xxx.xxx.54256: Flags [S.], seq 3537213936, ack 2188358662, win 65535, options [mss 16344,nop,wscale 4,nop,nop,TS val 162534351 ecr 162534351,sackOK,eol], length 0
Another problem is that none of the windows clients get IP addresses from the DHCP server. When setting addresses manually they work fine.
Any ideas or help really appreciated. Thank you!
Mac mini, OS X Mavericks (10.9.5), Server 3.2.1