>>> On 19 July 2007 at 18:55, in message <[EMAIL PROTECTED]>, Dag Richards <[EMAIL PROTECTED]> wrote: > Gordon Ross wrote: >> So why is this different to what I put ? >> >> #These three lines allow the failover mechanisms to work >> pass on { $int_if } proto carp keep state >> pass on { $adsl_if } proto carp keep state >> pass quick on { $pfsync_if} proto pfsync [snip] > The difference is you were paying attention.
;-) > I really thought I saw pass out not just pass on your lines. > > When you do > > tcpdump -n -e -ttt -i pflog0 > > with rules enables to you see inbound carp being blocked? No CARP packets are being blocked. GTG