nat/outbound traffic not passing in pf on FreeBSD 6.1

Lyndon Nerenberg lyndon at orthanc.ca
Wed Jul 26 17:07:49 UTC 2006


> Well this is a silly question, but perhaps traffic is being passed
> out, but the responses can't get back in?  It's not clear to me how
> you expected responses to get in without a "keep state" on an outbound
> rule.

In the OpenBSD implementation, the 'nat' statement implicitly enables 
'keep state' behaviour, therefore a separate rule is not required.

--lyndon


More information about the freebsd-pf mailing list