That's a good idea and should work fine. I only need macros for the 5 NIC cards in each box.
Thanks, Brad > On Thursday 30 March 2006 21:33, Bradley W. Dutton wrote: >> Hi, >> >> I have 2 routers/firewalls setup with carp/pfsync that keep the network >> going with the same pf.conf. Unfortunately the hardware in these boxes >> is >> slightly different so the NICs have different names (em/sis/dc/etc). I >> have macros defined at the top of pf.conf for the NICs but I still have >> to >> change the macros each time I copy pf.conf from one box to the other. >> The >> OpenBSD PF page (http://www.openbsd.org/faq/pf/shortcuts.html) alludes >> to >> this scenario but I was wondering if there is a way to include more than >> one conf file? It would be nice to have one file contain the macros and >> the other contain all of the rules/queues/etc. >> >> What have others done in this scenario? Should I create a pf.conf >> template >> file and a script that swaps in the NIC names and copies the files to >> each >> of the boxes? > > You can use pfctl(8)'s -D switch to define the macros on the commandline > or > better in rc.conf(5)::pf_flags If you need plenty, that's not a perfect > sollution, I agree. In that case, I'd go for something like: > > cat /etc/pf.inc /etc/pf.conf | pfctl -f- > > -- > /"\ Best regards, | [EMAIL PROTECTED] > \ / Max Laier | ICQ #67774661 > X http://pf4freebsd.love2party.net/ | [EMAIL PROTECTED] > / \ ASCII Ribbon Campaign | Against HTML Mail and News > _______________________________________________ [email protected] mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-pf To unsubscribe, send any mail to "[EMAIL PROTECTED]"
