From owner-freebsd-pf@FreeBSD.ORG Mon Jul 26 15:02:27 2010 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 639A6106566B for ; Mon, 26 Jul 2010 15:02:27 +0000 (UTC) (envelope-from justin@sk1llz.net) Received: from sed.awknet.com (sed.awknet.com [69.42.208.18]) by mx1.freebsd.org (Postfix) with ESMTP id 538B88FC14 for ; Mon, 26 Jul 2010 15:02:27 +0000 (UTC) Received: from [192.168.1.64] (99-118-214-35.lightspeed.irvnca.sbcglobal.net [99.118.214.35]) by sed.awknet.com (Postfix) with ESMTP id 14E6F1082464 for ; Mon, 26 Jul 2010 15:02:27 +0000 (UTC) Message-ID: <4C4DA384.8030504@sk1llz.net> Date: Mon, 26 Jul 2010 08:02:28 -0700 From: Justin User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.11) Gecko/20100711 Thunderbird/3.0.6 MIME-Version: 1.0 To: freebsd-pf@freebsd.org References: <4C4D7EED.4060704@sk1llz.net> <20100726140545.GB72163@mail.hs.ntnu.edu.tw> In-Reply-To: <20100726140545.GB72163@mail.hs.ntnu.edu.tw> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Subject: Re: pf synproxy X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 26 Jul 2010 15:02:27 -0000 ... it's not an if_bridge, thanks. On 7/26/2010 7:05 AM, Denny Lin wrote: > On Mon, Jul 26, 2010 at 05:26:21AM -0700, Justin wrote: > >> Hello all - I've tried searching the list but it seems something is >> broken and I'm getting 500 errors. Alas, >> >> Is there something unique about using synproxy in a gateway style >> firewall that isn't outlined in the PF manuals? Here's the scenario: >> >> Internet -> em0 | pf rules | em1 -> target host. >> > Synproxy does not work when on bridges. > > From pf.conf(5): > Rules with synproxy will not work if pf(4) operates on a if_bridge(4). > >