Maybe I'm just confused, but my recollection is that one needs to set up
the appropriate hostname.<interface-name> to enable the interface before
the "egress" interface group works.
This single-NIC case is admittedly a minor one, but it would eliminate
one of the few (that I can think of) things about running a basic
OpenBSD system that requires any "arcane" setup.
Since I never mentioned eth0, the answer is pretty obviously "no".
See above.
Actually, it's other people who have the problem. I was just
speculating on how to minimize its harmful effects.
One can always postulate a hardware (or other) failure which can't be
dealt with by whatever the current software may be; the question is
whether it happens often enough and is serious enough to be worth doing
something about. Or if it suggests a change which is worthwhile in
itself and also solves the problem.
No, I'm thinking about a general way for those people who care about it
to tie pf rules, etc, to specific physical interfaces, regardless of
what other devices are installed or configured in a system.
Dave
--
Dave Anderson
<dave@daveanderson.com>