From owner-freebsd-pf@FreeBSD.ORG Mon Jul 26 14:21:29 2010 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id A61BA1065677 for ; Mon, 26 Jul 2010 14:21:29 +0000 (UTC) (envelope-from dennylin93@hs.ntnu.edu.tw) Received: from mail.hs.ntnu.edu.tw (mail.hs.ntnu.edu.tw [140.131.149.3]) by mx1.freebsd.org (Postfix) with ESMTP id 7B7208FC08 for ; Mon, 26 Jul 2010 14:21:29 +0000 (UTC) Received: by mail.hs.ntnu.edu.tw (Postfix, from userid 1001) id C85004B7825; Mon, 26 Jul 2010 22:05:45 +0800 (CST) Date: Mon, 26 Jul 2010 22:05:45 +0800 From: Denny Lin To: Justin Message-ID: <20100726140545.GB72163@mail.hs.ntnu.edu.tw> References: <4C4D7EED.4060704@sk1llz.net> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: <4C4D7EED.4060704@sk1llz.net> User-Agent: Mutt/1.4.2.3i Cc: freebsd-pf@freebsd.org Subject: Re: pf synproxy X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 26 Jul 2010 14:21:29 -0000 On Mon, Jul 26, 2010 at 05:26:21AM -0700, Justin wrote: > Hello all - I've tried searching the list but it seems something is > broken and I'm getting 500 errors. Alas, > > Is there something unique about using synproxy in a gateway style > firewall that isn't outlined in the PF manuals? Here's the scenario: > > Internet -> em0 | pf rules | em1 -> target host. Synproxy does not work when on bridges. >From pf.conf(5): Rules with synproxy will not work if pf(4) operates on a if_bridge(4). -- Denny Lin