Re: pf.conf: "match" seems to clean up previous "log" statements.

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Stuart Henderson
Date: Monday, June 14, 2010 - 8:28 am

On 2010-06-14, william dunand <william.dunand@gmail.com> wrote:

Ah, for that we can go simpler:

pass log
match

Now you would expect any outgoing traffic to be logged. It isn't.
I've sent a PR for this so it's not lost - it will probably be
kernel/6401.

You don't need it for your requirements though:


add "block out log on $ext_if proto tcp to port 25" here


move this nat-to rule above the pass rule/s that it needs to apply
to.

in general (excepting the bug demonstrated above), match rules
don't affect preceding rules.
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]