OpenBSD Journal

Allowing PF to skip interfaces

Contributed by grey on from the catching up on CVS changes dept.

Thanks to kris and several others writing in to let us know about this pf improvement from last week:

Introduce 'set skip on <ifspec>' to support a list of interfaces where no packet filtering should occur (like loopback, for instance). Code from Max Laier, with minor improvements based on feedback from deraadt@. ok mcbride@, henning@

The full commit message may be found here.

(Comments are closed)


Comments
  1. By Anonymous Coward (66.91.22.5) on

    this is nice. now i can have a public filtered and public unfiltered networks right through pf

  2. By Anonymous Coward (213.118.165.151) on

    So this does pretty much the same as "pass quick on <ifname>", but only a little bit faster? Or am I missing something obvious here?

    Comments
    1. By hackmann (212.242.231.41) on

      Yes, pretty much

    2. By djm@ (218.214.226.34) on

      It skips checking the state tree

Credits

Copyright © - Daniel Hartmeier. All rights reserved. Articles and comments are copyright their respective authors, submission implies license to publish on this web site. Contents of the archive prior to as well as images and HTML templates were copied from the fabulous original deadly.org with Jose's and Jim's kind permission. This journal runs as CGI with httpd(8) on OpenBSD, the source code is BSD licensed. undeadly \Un*dead"ly\, a. Not subject to death; immortal. [Obs.]