On Mon, Jan 21, 2008 at 12:31:35AM +1100, Sunnz wrote: > "Opposite direction is only defined in the context of a state entry, > and reply-to is useful only in rules that create state." - as far as I > know of, only TCP connections has states, but not UDP... so what I am > worried about is that reply-to does not work with UDP connections? I > don't have a UDP service to test this out now, but I probably will > have some UDP service in the future. pf keeps state on UDP (and ICMP) just fine.
-- Jussi Peltola