Re: lightly loaded system eats swap space

2018-06-25 Thread tech-lists
On 20/06/2018 06:08, Shane Ambler wrote: This review is aiming to fix this - https://reviews.freebsd.org/D7538 I have been running the patch on stable/11 and after eight days uptime I still have zero swap in use, I can't recall a time in the last few years that I have had no swap usage past the

Re: pf best practices: in or out

2018-06-25 Thread Aristedes Maniatis
On 25/6/18 5:30pm, Walter Parker wrote: The use case for pass out rules would be to block local processes on the box from making external connections to other servers. This is useful if you don't fully trust users or software running on your equipment. Also, this would useful to preemptively blo

Re: pf best practices: in or out

2018-06-25 Thread Aristedes Maniatis
Thanks Jason, So in essence, you'd just control everything on the 'pass in'. I'm assuming all traffic originating from the local machine is still hitting a pass in rule on some interface corresponding to the source IP address? DNAT is working fine for me in pf, although I understand it is nam