PF and tcpdump Label Patch

2006-06-21 Thread N. Ersen SISECI
Hello, I wrote a patch for PF to log "label" names like IPF's log-tag option. PF already has a label option to mark rules in `pfctl -sr `, but it does not write labels to log file, which is very usefull to match log entries to rules/or group of rules created by lists ( pass from any to any port {

Re: transparent proxy on bridge

2006-06-21 Thread Michael Vince
Roman Gorohov. wrote: Hello list. I'm planning to configure pf in bridged environment(using if_bridge on 6.1), so I have question if transparent proxy will work? Is the any working config, or some known issues? TIA, Roman Gorohov. ___ What kind o

Re: outgoing LAN traffic always in "keep state"

2006-06-21 Thread Travis H.
On 6/19/06, Ronnel P. Maglasang <[EMAIL PROTECTED]> wrote: one note, i observe that reply packets can match a rule(s) on the internal interface. When it passes through the firewall and out towards the LAN, right? > #normalize outgoing packets IP ID field > scrub log on vr0 all random

transparent proxy on bridge

2006-06-21 Thread Roman Gorohov.
Hello list. I'm planning to configure pf in bridged environment(using if_bridge on 6.1), so I have question if transparent proxy will work? Is the any working config, or some known issues? TIA, Roman Gorohov. ___ freebsd-pf@freebsd.org mailing list http