Re: PF divert-packet reinjection

2020-11-24 Thread Stuart Henderson
On 2020-11-23, Szél Gábor wrote: > Dear @misc > > We test OpenBSD with Suricata in IPS mode. > IPS mode requires PF divert-packet. > > simple rule to divert: > pass in log quick on $_if proto tcp from ! to any > divert-packet port 700 > > At first look everything is good! > The packet goes

PF divert-packet reinjection

2020-11-24 Thread Szél Gábor
Dear @misc We test OpenBSD with Suricata in IPS mode. IPS mode requires PF divert-packet. simple rule to divert: pass in log quick on $_if proto tcp from ! to any divert-packet port 700 At first look everything is good! The packet goes to suricata, suricata check packet, if packet is