pf doesn't honor net.inet.ip.forwarding?

Serguey Parkhomovsky xindigo at gmail.com
Wed Aug 11 23:07:58 UTC 2010


Hello,

pf seems to do NAT forwarding whether or not net.inet.ip.forwarding is
enabled. I set up a NAT between my webserver jail on lo1 and my
external interface on em0, and it works even when this setting is
disabled.

Here is the relevant part of my pf.conf:
nat on em0 from lo1 to any -> (em0)

Why does this work? Shouldn't pf be unable to forward packets when
net.inet.ip.forwarding=0?

- Serguey


More information about the freebsd-pf mailing list