> ooooppppsssss....
>
>
> O PF lê *todas* e utiliza a última que "bateu"
> aí, ele cria um "state"...

ooooooops

A menos que a regra contenha um quick.

"Filter rules are evaluated in sequential order, first to last. Unless
the packet matches a rule containing the quick keyword, the packet
will be evaluated against all filter rules before the final action is
taken"

http://www.openbsd.org/faq/pf/filter.html

-- 

http://www.webcrunchers.com/crunch/
-------------------------
Histórico: http://www.fug.com.br/historico/html/freebsd/
Sair da lista: https://www.fug.com.br/mailman/listinfo/freebsd

Responder a