pfctl -i

Jon Simola jsimola at gmail.com
Wed Aug 15 00:38:04 UTC 2007


On 8/14/07, Toomas Pelberg <toomas at detalem.cq.hk> wrote:
> pfctl man page says:
>
> -i interface
>              Restrict the operation to the given interface.
>
> ..what exactly is meant under the word "operation" ?

This would be one of those things that is obvious once you've seen an example
and thought about it for a while.

$sudo pfctl -si |grep -A1 State
State Table                          Total             Rate
  current entries                    34056
$sudo pfctl -i vlan170 -ss |wc -l
    1172

In this case, only show states bound to the vlan170 interface.

> My problem: I want to load a different ruleset for each interface
> ( jails ) and not care about what's in the ruleset as long as it doesn't
> affect anything outside the jail ( which is bound to a specific ip on a
> seperate interface )

You probably want to look into anchors.

-- 
Jon


More information about the freebsd-pf mailing list