>>> On 20 July 2007 at 10:04, in message <20070720090413.GK3317@bootes.spacehopper.org>, Stuart Henderson <stu@spacehopper.org> wrote:destination, Phew ! I thought my brain had gone the same way as my hair... ;-) I did: pass in on $int_if proto tcp from 172.16.2.34 to 192.168.249.3 keep state pass out on $out_if and that worked. I then did: pass in on $int_if proto tcp from 172.16.2.34 to 192.168.249.3 tag TEST_TAG keep state pass out on $out_if tagged TEST_TAG and that worked as well - and (I believe) is tighter than just a "pass out". (Certainly solves my paranoid problem in my previous posting) Going off on a tangent here: Why is it that I've just picked this up and no-one else has ? Is it because I'm running in full paranoia mode and blocking *everything* unless explicitly allowed ? I haven't tried your diff - let me know if you want me to. Thanks for your help, much appreciated. GTG
| Greg KH | [GIT PATCH] driver core patches against 2.6.24 |
| Greg KH | [patch 00/04] RFC: Staging tree (drivers/staging) |
| James Bottomley | Re: Integration of SCST in the mainstream Linux kernel |
| Steven Rostedt | [RFC PATCH 1/3] Unified trace buffer |
git: | |
| Jon Smirl | ! [rejected] master -> master (non-fast forward) |
| Marco Costalba | [ANNOUNCE] qgit4 aka qgit ported to Windows |
| Andi Kleen | Re: [kernel.org users] [RFD] On deprecating "git-foo" for builtins |
| Sverre Rabbelier | Git vs Monotone |
| Richard Stallman | Real men don't attack straw men |
| GVG GVG | ssh_exchange_identification: Connection closed by remote host |
| Damian Gerow | Oddly high load average |
| Benjamin Adams | BSD Port from OpenJDK |
| Michael Grollman | Re: 8169 Intermittent ifup Failure Issue With RTL8102E Chipset in Intel's New D945... |
| Volker Armin Hemmann | build error with 2.6.27.6+reiser4+ehci-hub patch. ERROR: "mii_ethtool_gset" [drive... |
| Evgeniy Polyakov | [resend take 2 0/4] Distributed storage. |
| Wenji Wu | A Linux TCP SACK Question |
