Re: Source address selection algorithm w/ bgp

2020-05-29 Thread Pierre Emeriaud
Le jeu. 28 mai 2020 à 17:19, Denis Fondras a écrit : > > I have a pf.conf with : > pass out on $if_ix from $ip_ix to !$subnet_ix nat-to $ip_router > > Not a definitve solution but does the work on a low-traffic bgp router :/ Thanks Denis, this is what I'm currently doing, but this is more a

Re: Source address selection algorithm w/ bgp

2020-05-29 Thread Pierre Emeriaud
Le jeu. 28 mai 2020 à 16:09, Theo de Raadt a écrit : > > A few tools have options like -s, but it is a problem. > > I'm also frustrated by this solution, and working on a better method. thanks for acknowledging this issue Theo. Just wanted to check if I hadn't missed anything obvious.

Re: Source address selection algorithm w/ bgp

2020-05-28 Thread Denis Fondras
On Thu, May 28, 2020 at 08:09:25AM -0600, Theo de Raadt wrote: > A few tools have options like -s, but it is a problem. > > I'm also frustrated by this solution, and working on a better method. > > Pierre Emeriaud wrote: > > > What is the current canonical way to tweak source address

Re: Source address selection algorithm w/ bgp

2020-05-28 Thread Theo de Raadt
A few tools have options like -s, but it is a problem. I'm also frustrated by this solution, and working on a better method. Pierre Emeriaud wrote: > What is the current canonical way to tweak source address selection? > > I have a bgp multi-homed router, and while answers do use the correct

Source address selection algorithm w/ bgp

2020-05-28 Thread Pierre Emeriaud
Hello Hi misc@ What is the current canonical way to tweak source address selection? I have a bgp multi-homed router, and while answers do use the correct source address, host-generated traffic uses the outgoing interface IP address: $ route -n get 194.2.0.20 route to: 194.2.0.20 destination: