pf and bridging

Max Laier max at love2party.net
Fri Dec 3 06:47:26 PST 2004


On Thursday 02 December 2004 19:45, Petr Holub wrote:
> Hi all,
>
> I wonder if it is possible to use the new pf firewall together with
> bridging as it is possible to use it with ipf and ipfw.

Unfortunately the PFIL_HOOKS in bridge.c don't work too well for pf (or ipf 
for the same reason) thus you cannot use stateful filtering. There is an 
ongoing discussion on freebsd-pf@ that talks about the details:
http://lists.freebsd.org/pipermail/freebsd-pf/2004-December/000621.html
http://lists.freebsd.org/pipermail/freebsd-pf/2004-December/000625.html
http://lists.freebsd.org/pipermail/freebsd-pf/2004-December/000631.html

-- 
/"\  Best regards,                      | mlaier at freebsd.org
\ /  Max Laier                          | ICQ #67774661
 X   http://pf4freebsd.love2party.net/  | mlaier at EFnet
/ \  ASCII Ribbon Campaign              | Against HTML Mail and News
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 187 bytes
Desc: not available
Url : http://lists.freebsd.org/pipermail/freebsd-net/attachments/20041203/a2132c3a/attachment.bin


More information about the freebsd-net mailing list