Contributed by jose on from the new-features dept.
Subject: Source Tracking in PF From: Ryan McBrideRead Ryan's mail for a longer description of how to do this. Those of you multihoming or load balancing with PF are going to love this.Date: 2003-12-15 0:23:58 I just committed code which adds support to track stateful connections by source IP address. This allows a user to: - Ensure that clients get a consistent IP mapping with load-balanced translation/routing rules - Limit the number of simultaneous connections a client can make - Limit the number of clients which can connect through a rule As always, the more people who test this and provide feedback, the happier I am. Read below for details. -Ryan
(Comments are closed)
By Anonymous Coward () on
Thanks!
Comments
By Anonymous Coward () on
By Anonymous Coward () on
By gwyllion () on
Add initial support for pf state synchronization over the network.
Implemented as an in-kernel multicast IP protocol.
Turn it on like this:
# ifconfig pfsync0 up syncif fxp0
There is not yet any authentication on this protocol, so the syncif must be on a trusted network. ie, a crossover cable between the two firewalls.
By Anonymous Coward () on
The following rule allows a maximum of 1000 source ip's to connect to a webserver, each with a maximum of 3 simultaneous states: pass in on $ext_if proto tcp to $webserver port www flags S/SA keep state (source-track, max-src-states 3, max-src-nodes 10)
Shouldn't that be "max-src-nodes 1000" instead of 10? Just wanting to make sure I understood the example correctly. :)
Comments
By Foxy () foxy@free.fr on http://foxy.free.fr