> Ok. "floating" is the default, and is what PF has been doing all the time. > That mean that if you've a rule like: > > pass in on fxp0 keep state > > Once the state is created, PF will match that state with packets having > the same characteristics (source/dest IP, same port for UDP/TCP, ...) > coming in/out *any* interface. So, if a state is created for IKE traffic > coming in on one interface, then any IKE packet with spoofed IP will be > able to enter the firewall from any other interface, regardless of PF > rules on that interface.
i can't find the discussion with daniel, where he pointed out: "this is the pf.conf manual page issue in saying: "... If a packet matches a pass ... keep state rule, the filter creates a state for this connection and automatically lets pass all subsequent packets of that connection." also, he pointed what "now, the state is BOUNDED to interface". that's why we always do block log all pass on $int pass out on $ext from ($ext) to any keep state instead of just block log all pass out on $ext from ($ext) to any keep state correct me, if i wrong...
