From owner-freebsd-pf@FreeBSD.ORG Fri Mar 18 11:47:31 2011 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 2189B1065677 for ; Fri, 18 Mar 2011 11:47:31 +0000 (UTC) (envelope-from melissa-freebsdstable@littlebluecar.co.uk) Received: from filter.blacknosugar.com (filter.blacknosugar.com [212.13.204.214]) by mx1.freebsd.org (Postfix) with ESMTP id C295D8FC1B for ; Fri, 18 Mar 2011 11:47:30 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=littlebluecar.co.uk; s=dkim; h=Subject:To:References:Message-Id:Content-Transfer-Encoding:Date:In-Reply-To:From:Mime-Version:Content-Type; bh=/ZDXUy8Ew0/vlslA0Fb53df1lTFdgYFcgb/KiKUIQG4=; b=pLDVEv57k+L429JYWQk2rdGjsqC4dS8mQ52C63C1TRLlgiKPtP87DHeuz9guCc0FBlWKt72DgfXeL2NZcYTFFMOcAbNa+WUAwo8aFmEN7z7YnVq0cCVa2fh7uY7swEAh; Received: from bowser.blacknosugar.com ([78.86.203.16] helo=[192.168.1.59]) by filter.blacknosugar.com with esmtpsa (TLSv1:AES128-SHA:128) (Exim 4.74 (FreeBSD)) (envelope-from ) id 1Q0Xtm-0003i2-IQ for freebsd-pf@freebsd.org; Fri, 18 Mar 2011 11:31:30 +0000 Content-Type: text/plain; charset=us-ascii Mime-Version: 1.0 (Apple Message framework v1082) From: Melissa Jenkins In-Reply-To: <20110131112244.839B610656A8@hub.freebsd.org> Date: Fri, 18 Mar 2011 11:31:12 +0000 Content-Transfer-Encoding: quoted-printable Message-Id: <9C34D3E1-5F82-461B-AD1D-9BD7402D794E@littlebluecar.co.uk> References: <20110131112244.839B610656A8@hub.freebsd.org> To: freebsd-pf@freebsd.org X-Mailer: Apple Mail (2.1082) X-SA-Exim-Connect-IP: 78.86.203.16 X-SA-Exim-Mail-From: melissa-freebsdstable@littlebluecar.co.uk X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on filter X-Spam-Level: X-Spam-Status: No, score=-2.9 required=5.0 tests=ALL_TRUSTED,BAYES_00 autolearn=ham version=3.3.1 X-SA-Exim-Version: 4.2 X-SA-Exim-Scanned: Yes (on filter.blacknosugar.com) Subject: PFsync & RDR/NAT X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 18 Mar 2011 11:47:31 -0000 Hiya, I was wondering if anybody knew how to stop the states generated by RDR = and NAT rules from synchronising over PFSYNC? In particular I have an RDR for DNS traffic. The states this produces = don't need to be synchronised between the two machines, but I can't = figure out how to stop this. Adding the (no state) flags to the pass = rule doesn't stop the states from being synchronised. Thanks! Mel=