https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=226850

--- Comment #23 from commit-h...@freebsd.org ---
A commit references this bug:

Author: kp
Date: Fri Jun 29 16:46:20 UTC 2018
New revision: 335798
URL: https://svnweb.freebsd.org/changeset/base/335798

Log:
  MFC r335569:

  pf: Support "return" statements in passing rules when they fail.

  Normally pf rules are expected to do one of two things: pass the traffic or
  block it. Blocking can be silent - "drop", or loud - "return", "return-rst",
  "return-icmp". Yet there is a 3rd category of traffic passing through pf:
  Packets matching a "pass" rule but when applying the rule fails. This happens
  when redirection table is empty or when src node or state creation fails.
Such
  rules always fail silently without notifying the sender.

  Allow users to configure this behaviour too, so that pf returns an error
packet
  in these cases.

  PR:           226850
  Submitted by: Kajetan Staszkiewicz <vegeta tuxpowered.net>
  Sponsored by: InnoGames GmbH

Changes:
_U  stable/11/
  stable/11/sbin/pfctl/parse.y
  stable/11/share/man/man5/pf.conf.5
  stable/11/sys/netpfil/pf/pf.c

-- 
You are receiving this mail because:
You are the assignee for the bug.
_______________________________________________
freebsd-pf@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-pf
To unsubscribe, send any mail to "freebsd-pf-unsubscr...@freebsd.org"

Reply via email to