Re: make pf allow out on lo per user

2017-01-25 Thread Alexander Hall
On January 26, 2017 6:54:54 AM GMT+01:00, Alexander Hall wrote: >On January 25, 2017 10:44:19 AM GMT+01:00, "Peter N. M. Hansteen" > wrote: >>On Wed, Jan 25, 2017 at 12:04:40AM +, Luke Small wrote: >>> if I have: >>> "pass out quick on lo0 from self port 6379 to \ any user luke >>> >>> block o

Re: make pf allow out on lo per user

2017-01-25 Thread Alexander Hall
On January 25, 2017 10:44:19 AM GMT+01:00, "Peter N. M. Hansteen" wrote: >On Wed, Jan 25, 2017 at 12:04:40AM +, Luke Small wrote: >> if I have: >> "pass out quick on lo0 from self port 6379 to \ any user luke >> >> block out quick on lo0 from self port 6379 to any >> >> pass quick on lo0 from

Re: make pf allow out on lo per user

2017-01-25 Thread Peter N. M. Hansteen
On Wed, Jan 25, 2017 at 12:04:40AM +, Luke Small wrote: > if I have: > "pass out quick on lo0 from self port 6379 to \ any user luke > > block out quick on lo0 from self port 6379 to any > > pass quick on lo0 from any to any" > > a local connection to port 6379 will go to the last rule... is

Re: make pf allow out on lo per user

2017-01-24 Thread Emille Blanc
On 24.01.2017 16:04, Luke Small wrote: if I have: "pass out quick on lo0 from self port 6379 to \ any user luke block out quick on lo0 from self port 6379 to any pass quick on lo0 from any to any" a local connection to port 6379 will go to the last rule... isn't this a useful feature to allo

make pf allow out on lo per user

2017-01-24 Thread Luke Small
if I have: "pass out quick on lo0 from self port 6379 to \ any user luke block out quick on lo0 from self port 6379 to any pass quick on lo0 from any to any" a local connection to port 6379 will go to the last rule... isn't this a useful feature to allow one of the first two rules to take effect