Re: How pf chooses nics on bridges?

2015-04-29 Thread Henning Brauer
* Listas IT listas...@dna.uba.ar [2015-04-28 21:20]: Why is it that blocked packets appear sometimes on fxp0 and sometimes on vether0? it's simply the interface the packet came in on. Thank you. I get that. The question is why sometimes it logs fxp0 and sometimes is vether0 as both are

Re: How pf chooses nics on bridges?

2015-04-28 Thread Henning Brauer
* Listas IT listas...@dna.uba.ar [2015-04-28 11:25]: We have a 5.6-stable box doing transparent filtering with pf. blog log all is default on ruleset. The bridge is composed of fxp0 and vether0 on int net 192.168.192/23 and xl0 (internet). While doing normal work pflog0 shows this:

How pf chooses nics on bridges?

2015-04-28 Thread Listas IT
Hello We have a 5.6-stable box doing transparent filtering with pf. blog log all is default on ruleset. The bridge is composed of fxp0 and vether0 on int net 192.168.192/23 and xl0 (internet). While doing normal work pflog0 shows this: 06:19:08.497855 rule 17/(match) block in on vether0:

Re: How pf chooses nics on bridges?

2015-04-28 Thread Listas IT
06:19:08.497855 rule 17/(match) block in on vether0: 192.168.193.41.3138 77.234.44.65.80: tcp 0 (DF) 06:19:08.546275 rule 17/(match) block in on fxp0: 192.168.193.28.59751 77.234.44.76.443: tcp 0 (DF) 06:19:08.582708 rule 17/(match) block in on fxp0: 192.168.192.146.61276