From owner-freebsd-pf@FreeBSD.ORG Thu Mar 10 17:37:05 2005 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id C87F816A4D2 for ; Thu, 10 Mar 2005 17:37:05 +0000 (GMT) Received: from rproxy.gmail.com (rproxy.gmail.com [64.233.170.193]) by mx1.FreeBSD.org (Postfix) with ESMTP id 1B74343D31 for ; Thu, 10 Mar 2005 17:37:05 +0000 (GMT) (envelope-from mclone@gmail.com) Received: by rproxy.gmail.com with SMTP id g11so964097rne for ; Thu, 10 Mar 2005 09:37:03 -0800 (PST) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:reply-to:to:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:references; b=gUKfQYJ27rO/FXNJS1ocKqAgu2Ql5N7Z7zR25v+GTG5HwrPrAIhFLsJKyLrmFgXkbUKOZajOUfJ5u+z6u5LnrI48rAQeR9fT93MEl36EzdtHZD6Yenztzlthaur90yqkRie5poRwLA732RXJapE0Wd2+obRutI+8oT2kWi7ILjk= Received: by 10.11.120.7 with SMTP id s7mr85182cwc; Thu, 10 Mar 2005 09:37:03 -0800 (PST) Received: by 10.11.98.7 with HTTP; Thu, 10 Mar 2005 09:37:03 -0800 (PST) Message-ID: <451cb301050310093753511884@mail.gmail.com> Date: Thu, 10 Mar 2005 19:37:03 +0200 From: McLone To: jon@abccomm.com, freebsd-pf@freebsd.org In-Reply-To: <8eea040805030521005347c44e@mail.gmail.com> Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit References: <62956.81.30.200.207.1110031162.squirrel@81.30.200.207> <8eea040805030521005347c44e@mail.gmail.com> Subject: Re: pfsync + pfflowd + flow-tools (ifconfig maxupd)? X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: McLone List-Id: Technical discussion and general questions about packet filter (pf) List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 10 Mar 2005 17:37:05 -0000 On Sat, 5 Mar 2005 21:00:18 -0800, Jon Simola wrote: > All the PF and CARP docs suggest a dedicated interface for pfsync, > mostly due to security issues. The most common implementation I would > assume is a pair of firewalls each with 3 interfaces (internal, > external, and sync connected via a xover cable). one can do tunneling, right? -- wbr, |\ _,,,---,,_ dog bless ya! ` Zzz /,`.-'`' -. ;-;;,_ McLone at GMail dot com |,4- ) )-,_. ,\ ( `'-' net- and *BSD admin '---''(_/--' `-'\_) ...sorry for translit