Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 10 Oct 2017 16:11:23 +0000
From:      Mark Raynsford <list+org.freebsd.pf@io7m.com>
To:        freebsd-pf@freebsd.org
Subject:   Specifying a range of ipv6 addresses?
Message-ID:  <20171010161123.52808204@copperhead.int.arc7.info>

next in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Hello.

What is the syntax for specifying a range of IPv6 addresses in rules?

I want to write rules of the form:

pass out log quick on $nic_ppp inet6 proto tcp from
2001:db8:8:10::/64 to any port 80 modulate state

But pf appears to treat 2001:db8:8:10::/64 as a single address (I
intended it to mean an entire subnet).

-- 
Mark Raynsford | http://www.io7m.com

[-- Attachment #2 --]
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEgWja4isV0+3HIsI9DxW30G+oDLgFAlnc8SsACgkQDxW30G+o
DLid/w/9G9EM6QQ3/ilLjfz1xSuzK5QIIY9lbFCvjrnfz3CVAyJSdwUbsZguY3LU
Nmdv0D3yUzL2TcRvFushl6PbA8qhkRdIBpLX7CH3x6aAi5qw6oclDQ3vNpH5YmmQ
T1WBP7+gwD9jqkJ5CDdsF7+4HNYq8/H1V7/uZRqKNgZC+ZqSrOqt0/8eqnnNkQYL
eqP297snoPbyB7VyHFOal6DXHIBYuTmKZxfDNy/8PnT3MwhYZqWIdIGG8ui26WLs
2x/nmrgLIHnKYRDv2mYi44cd47ysiXviM5BlrsQsfeQFluwzWV+D6Q9nRDGEslTJ
AD8atxTXPsVE8X1NDnsidy+puS7lcAlhVdKCMqOSmKbLl+qlCvWSuDfKhgQ3Zp1n
lpF8JDsOFjuBNLm8vQr350p8vufOElTotm9085+mnWAiTtV/7lLsUCNgKd4JuKwq
CIqnAv2S8EFc6B0ZXFI2KmyFMjteBmbmAcB8eLZ3S9BEmzUrQQkN+QYoqu9Ej0yt
Ze+w7g2qMlceGzzHGVz8sWU0JKCOezRzX5PgAO6lIEa3BZRwYV58DjJ91YKnSLs2
pHdAx1w9B549V+FyVVI4f9JEDvPAAxDGGEHC2Em+0sTZwWu6EAfc9mqOi7DvQz9B
dCq3eSr5hhM7Tl88kDIIxKjViC7wS8masraBZ/ICLmRJ10VGrPI=
=UwMG
-----END PGP SIGNATURE-----

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20171010161123.52808204>