Rules sanity check

2015-10-12 Thread David Mehler
Hello, I'm back to pf after a number of years with mainly Linux servers. I'm running FreeBSD 10 on a machine with pf. I'm hoping someone can give my rules such as they are a sanity check? Some things I know definitely aren't working is the ipv6 allowing of ssh and http, ipv6 ping doesn't work giv

RE: Creating span interface using 'dup-to' option

2015-10-12 Thread David DeSimone
The man page makes it clear that "dup-to" acts just like "route-to", except that the original packet still routes the way it would have. The implication being that "dup-to" needs to determine where to route the new packet. This means that the more useful form of this is likely to be: pass

Re: Creating span interface using 'dup-to' option

2015-10-12 Thread MiƂosz Kaniewski
2015-10-11 23:19 GMT+02:00 Kristof Provost : > > From a quick test, yes, it looks like something's broken, or we're both > misunderstanding something. > > My system complains 'arpresolve: can't allocate llinfo for 8.8.8.8 on > vtnet1'. > I think the issue is that we still try to resolve the destin