Henning Brauer wrote:

that is in practice true for 99% of you.

the state key does not include the interface, but the direction.
as long as routes do not change that is equivalent to beeing bound to
the interface.

Yes, for "normal" (i.e. not spoofed) packets.
In fact, I think everybody that is running a firewall where routes do
not change should define "set state-policy if-bound", because it will
protect a bit better against spoofed packets.
The other benefit of doing so is that the output of "pfctl -ss" can be
easily broken down by interface with just a "| grep fxp0"...
Very useful when dealing with many interfaces on the firewall :)
Cedric




Reply via email to