need help with pf configuration

Patrick Lamaiziere patfbsd at
Sun Oct 9 09:27:58 UTC 2011

Le Sun, 9 Oct 2011 14:39:10 +0700,
Victor Sudakov <vas at> a écrit :

> > > I need no details, just a general hint how to setup such security
> > > levels, preferably independent of actual IP addressses behind the
> > > interfaces (a :network macro is not always sufficient).
> > 
> > You may use urpf-failed instead :network
> > urpf-failed: Any source address that fails a unicast reverse path
> > forwarding (URPF) check, i.e. packets coming in on an interface
> > other than that which holds the route back to the packet's source
> > address.
> Excuse me, I do not see how this is relevant to my question (allowing
> traffic to be initiated from a more secure interface to a less secure
> interface and not vice versa).

Sorry, you can't do this with pf, ipf or ipfw (the 3 firewalls in
FreeBSD). There is no concept of security level at all, you must specify
on each interface the traffic allowed (in input and output).

My reply was about the use of the interface:network addresses.


More information about the freebsd-questions mailing list