Yes, I too thought that the <martians> table could be the reason and even
tried to completely comment out the rules with this table. That did not
help and I later understood why. The rules with the <martians> table
affect the network stream on egress port which is vether0 by me. But
these rules do not apply neither to em0 nor em2. These are part of the
same virtual bridge0 as vether0 but they are not filtered.
As I understand if the iptv stream is blocked by PF it should be logged
by the rule "block log all". But there are no packets when I do "tcpdump
-n -e -i pflog0 not ifname vether0 and action block"

--
Best regardsMaksim Rodin

18:41, 18 июня 2019 г., Stuart Henderson <s...@spacehopper.org>:

  On 2019-06-18, Максим <a23s4a2...@yandex.ru> wrote:

    � When I disable PF and use tcpdump to monitor network activity
    on em2
    � (where the IPTV box is connected) I see a stream of udp packets
    (something like this:
    � 233.33.210.7:5050)
    � This stream is interrupted in several seconds when I enable PF
    again.


  It probably doesn't help that you have the multicast address range
  in your <martians> table ..

Reply via email to