Re: pf and new interface

2015-08-21 Thread Andriy Gapon
On 18/08/2015 20:43, Reko Turja wrote: > Hmm does the: > > set skip on (tap) > > syntax work in this case? Basically parentheses around the alias should > tell pf that the IP is volatile and can be either activated at later > time or it can be dynamic via dhcp etc. It seems that this would be a

Re: pf and new interface

2015-08-18 Thread Andriy Gapon
On 18/08/2015 20:43, Reko Turja wrote: > Hmm does the: > > set skip on (tap) > > syntax work in this case? Basically parentheses around the alias should > tell pf that the IP is volatile and can be either activated at later > time or it can be dynamic via dhcp etc. I will check and follow up. -

Re: pf and new interface

2015-08-18 Thread Reko Turja
Hmm does the: set skip on (tap) syntax work in this case? Basically parentheses around the alias should tell pf that the IP is volatile and can be either activated at later time or it can be dynamic via dhcp etc. -Reko ___ freebsd-net@freebsd.or

Re: pf and new interface

2015-08-18 Thread Andriy Gapon
On 18/08/2015 14:55, wishmaster wrote: > --- Original message --- > From: "Andriy Gapon" > Date: 18 August 2015, 14:35:36 > > > >> On 18/08/2015 14:18, wishmaster wrote: >>> --- Original message --- >>> From: "Andriy Gapon" >>> Date: 18 August 2015, 14:05:15 >>> >>> I have the follow

Re[2]: pf and new interface

2015-08-18 Thread wishmaster
--- Original message --- From: "Andriy Gapon" Date: 18 August 2015, 14:35:36 > On 18/08/2015 14:18, wishmaster wrote: > > --- Original message --- > > From: "Andriy Gapon" > > Date: 18 August 2015, 14:05:15 > > > > > >> I have the following rule in pf.conf: > >> set skip on tap > >>

Re: pf and new interface

2015-08-18 Thread Andriy Gapon
On 18/08/2015 14:18, wishmaster wrote: > --- Original message --- > From: "Andriy Gapon" > Date: 18 August 2015, 14:05:15 > > >> I have the following rule in pf.conf: >> set skip on tap >> and even the following one: >> set skip on tap0 >> >> The rules are loaded at the system start-up time, b

Re: pf and new interface

2015-08-18 Thread wishmaster
  --- Original message --- From: "Andriy Gapon" Date: 18 August 2015, 14:05:15 > I have the following rule in pf.conf: > set skip on tap > and even the following one: > set skip on tap0 > > The rules are loaded at the system start-up time, but the tap interface > may not be created until m

pf and new interface

2015-08-18 Thread Andriy Gapon
I have the following rule in pf.conf: set skip on tap and even the following one: set skip on tap0 The rules are loaded at the system start-up time, but the tap interface may not be created until much later. When tap0 is first created the skip rules are not applied to it and the traffic gets fil