Re: pf: match vs. pass - nat and rdr

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: nixlists
Date: Tuesday, January 5, 2010 - 7:49 pm

On Tue, Jan 5, 2010 at 8:34 PM, Robert <robert@openbsd.pap.st> wrote:

....


But  'pass' still works:

pass out on em0 inet from 192.168.1.0/24 to any flags S/SA keep state
nat-to (em0) round-robin


No, I am saying I killed the box by removing a single existing rule
from the ruleset and running systat.  it froze as soon as I ran
'systat queues' . After a reboot the box has no trouble running the
ruleset.


Hmm... I simply copied the example, and my internal interface became
bandwidth-limited as in the example.

Thanks.
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
pf: match vs. pass - nat and rdr, nixlists, (Tue Jan 5, 4:15 pm)
Re: pf: match vs. pass - nat and rdr, Robert, (Tue Jan 5, 6:34 pm)
Re: pf: match vs. pass - nat and rdr, nixlists, (Tue Jan 5, 7:49 pm)
Re: pf: match vs. pass - nat and rdr, Henning Brauer, (Fri Jan 8, 8:31 pm)