Re: pf and tap interfaces

2021-10-31 Thread tech-lists
On Sun, Oct 31, 2021 at 10:13:06AM -0600, Theo de Raadt wrote: you are asking a freebsd question on an openbsd mailing list. come on You may have missed my response to Sebastian: In-Reply-To: On Sun, Oct 31, 2021 at 03:59:40PM +, tech-lists wrote: [...] All I'm really asking at this

Re: pf and tap interfaces

2021-10-31 Thread Theo de Raadt
tech-lists wrote: > On Sun, Oct 31, 2021 at 09:33:54AM -0600, Theo de Raadt wrote: > >tech-lists wrote: > > > >> I'm asking this here because I'm trying to do this with FreeBSD but > >> their pf has diverged a lot from OpenBSD's > > > >that is incorrect history. > > > >It is hard to see how 'abs

Re: pf and tap interfaces

2021-10-31 Thread tech-lists
On Sun, Oct 31, 2021 at 09:33:54AM -0600, Theo de Raadt wrote: tech-lists wrote: I'm asking this here because I'm trying to do this with FreeBSD but their pf has diverged a lot from OpenBSD's that is incorrect history. It is hard to see how 'absolutely minimal maintainance' can result in di

Re: pf and tap interfaces

2021-10-31 Thread tech-lists
Hi, On Sun, Oct 31, 2021 at 04:23:58PM +0100, Sebastian Benoit wrote: Maybe you could describe a bit more what you are trying to do. I'm trying to protect, with pf, a freebsd host running bhyve guests. The guests use tap interfaces. They are in the same network as the host (but with different

Re: pf and tap interfaces

2021-10-31 Thread Theo de Raadt
tech-lists wrote: > I'm asking this here because I'm trying to do this with FreeBSD but > their pf has diverged a lot from OpenBSD's that is incorrect history. It is hard to see how 'absolutely minimal maintainance' can result in divergence. At some point, pf's state table data structures were

Re: pf and tap interfaces

2021-10-31 Thread Sebastian Benoit
tech-lists(tech-li...@zyxst.net) on 2021.10.31 15:10:57 +: > Hello misc@ > > Generically, can OpenBSD [7.0] apply rules to *just* the ethernet > interface, ignoring the bridge and tap interfaces? Can it do this > natively or is a VLAN required as well? Or something else? > > I'm asking this h

pf and tap interfaces

2021-10-31 Thread tech-lists
Hello misc@ Generically, can OpenBSD [7.0] apply rules to *just* the ethernet interface, ignoring the bridge and tap interfaces? Can it do this natively or is a VLAN required as well? Or something else? I'm asking this here because I'm trying to do this with FreeBSD but their pf has diverged a