pf, stateful filter and DMZ

Victor Sudakov vas at
Sun Dec 1 14:38:56 UTC 2019

There is still one thing I cannot understand about pf's notion of state. 

Consider this very simple example:

pass in on $dmz
#block in on $dmz from any to

# Inside
pass in on $inside

While the "block ..." line is commented out, I can "telnet 80" from
But when I uncomment the "block ..." line and restart pf, I cannot do
that any more. Why is that?

My idea was that the "pass in on $inside" creates state so that return
traffic from to should be permitted, but this
is not happening. Why?

Victor Sudakov,  VAS4-RIPE, VAS47-RIPN
2:5005/49 at fidonet
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 455 bytes
Desc: not available
URL: <>

More information about the freebsd-net mailing list