Sorry, but with PF is it possible to discriminate between an access from a particular interface? If so, I think it is more secure to give webconsole access only to connection coming from the "secure " interface... Am I wrong?


On 8/11/05, Scott Ullrich <[EMAIL PROTECTED]> wrote:
Correct.  Which now brings us round circle to why you have to add a
rule for the WAN if there is no LAN ip to access to administrate the
box.

On 8/11/05, Tommaso Di Donato < [EMAIL PROTECTED]> wrote:
>
>
> > >  If so, why not add an option, just to permit webconsole access only to
> > > connection coming fron the lan interface?
> >
> > Because if there is no IP on the lan what is there to surf into?
> >
>
>  Directly to the ip assigned to wan interface...
>
>  I am coming from Linux, I hope I am not missing something because of the
> differences between iptables and PF....
>

Reply via email to