Max Laier wrote:
On Thursday 04 December 2008 16:47:13 Max Laier wrote:
On Thursday 04 December 2008 16:24:23 Vladimir Ermakov wrote:
problem is fixed in OpenBSD 4.4
http://www.openbsd.org/plus44.html
The bug this note refers to was introduced after OpenBSD 4.1 (our last
import) and should not be present in the FreeBSD code.  I'll double check
in a bit to make sure synproxy is working, but I don't think it was broken
after my last import ... do you have a particular test case that I could
reproduce?

Okay ... here is the story: First off, "synproxy state" is *NOT* broken! But you need to be careful how you use it. If you - like the OP - intend to use it to protect a service running on the same box as your pf, you must make sure to "set skip on lo0" or it will not work. If you are protecting a box behind the pf box, there is no need for that.

Can a `synproxy state` to work on the CARP interface?

/Vladimir Ermakov


_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-pf
To unsubscribe, send any mail to "[EMAIL PROTECTED]"

Reply via email to