pf and new interface

Andriy Gapon avg at FreeBSD.org
Tue Aug 18 08:16:51 UTC 2015


I have the following rule in pf.conf:
set skip on tap
and even the following one:
set skip on tap0

The rules are loaded at the system start-up time, but the tap interface
may not be created until much later.  When tap0 is first created the
skip rules are not applied to it and the traffic gets filtered.  If I
reload the pf configuration, then the rules start working.

Is there a way to make pf honor such rules for the dynamic interfaces?

-- 
Andriy Gapon


More information about the freebsd-net mailing list