On Sat, Nov 29, 2008 at 6:51 PM, DLStrout <[EMAIL PROTECTED]> wrote:
> I did as you'd said below and found no difference,
> but one thing I did notice is that when doing the
> upgrade that ("I thought") broke reflective
> routing appears to have "unchecked" the option
> under the advanced section about bypassing rules
> for networks that share the same interface.
>

As I said.


> I am doing some testing to see if I can do route
> reflection without this option checked and by
> crafting some rules.

What you have is asymmetric routing. You can't statefully filter
traffic with any firewall if it's only seeing part of the connection.
If you manually add "no state" rules you can do without that. But now
that I thought of that, I just thought of a similar new bug - rules
specifying "no state" won't actually not keep state since that's the
default, one area we forgot about when looking for rules that don't
keep state.

I just fixed that, you can manually fix your install by applying this:
http://cvs.pfsense.com/cgi-bin/cvsweb.cgi/pfSense/etc/inc/filter.inc.diff?r1=1.575.2.368.2.91;r2=1.575.2.368.2.92;f=h

---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Commercial support available - https://portal.pfsense.org

Reply via email to