On Mon, 18 Jun 2018 12:08:33 +0200 "Kristof Provost" said
On 18 Jun 2018, at 0:19, Chris H wrote:
> Sorry. Looks like I might be coming to the party a little late. But
> I'm
> currently running a 9.3 box that runs as a IP (service) filter for
> much
> of a network. While I've patched the box
On Mon, 18 Jun 2018 12:21:47 +0200 "Kurt Jaeger" said
Hi!
> > So loading all entries in to empty table works fine, but reloading
> > didn't work.
> Sorry. Looks like I might be coming to the party a little late. But I'm
> currently running a 9.3 box that runs as a IP (service) filter for muc
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=229092
--- Comment #1 from Kajetan Staszkiewicz ---
I came across an issue preventing this from working correctly when rebooting
hardware: pfsync is started before pf (or in my case before my custom service
populating pf rules. That's a problem, b
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=226850
--- Comment #21 from Kajetan Staszkiewicz ---
Without this modification only "block" rules would be configured with
return-enabling flag and return ICMP codes. Modification in parse.y ensure that
"pass" rules are getting this information to
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=226850
--- Comment #20 from Kristof Provost ---
(In reply to Kajetan Staszkiewicz from comment #19)
I'm not sure I understand what the changes in 'action : PASS
{' (in parse.y) are for. Other than that, I think it's good.
--
Y
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=226850
Kajetan Staszkiewicz changed:
What|Removed |Added
Attachment #194340|0 |1
is obsolete|
Hi!
> > So loading all entries in to empty table works fine, but reloading
> > didn't work.
> Sorry. Looks like I might be coming to the party a little late. But I'm
> currently running a 9.3 box that runs as a IP (service) filter for much
> of a network. While I've patched the box well enough to
On 18 Jun 2018, at 0:19, Chris H wrote:
Sorry. Looks like I might be coming to the party a little late. But
I'm
currently running a 9.3 box that runs as a IP (service) filter for
much
of a network. While I've patched the box well enough to keep it safe
to
continue running. I am reluctant to up(