Management of pf.conf

2013-07-11 Thread Jummo
Hi, How do you manage your pf.conf? My setup: I have 9 firewalls with carp and each with around 500 lines of pf.conf, except one firewall, later more. I edit the pf.conf manually. Every logical pf rule has a unique identifier (a number) which I add manually and maps to the rule on a wiki page

pf: ICMP Ping with no state flag set not working

2013-01-17 Thread Jummo
Hi, I have just upgraded a OpenBSD 4.7 firewall to 5.2. The system routes between $net1 and $net2 with pf enabled. After the upgrade ping request from $net1 to $net2 get stuck (and vice versa). Only the first icmp echo-req from $net1 to $net2 get answered by a icmp echo-reply, all subsequent i