Re: pfctl -P -ss -vv -- sometimes eats cpu and becomes unkillable

2021-06-28 Thread Marek Zarychta
be now slow (really _SLOW_). Please try to run backed up pfctl(8) binary for displaying states (works in my case), if you have one. If you can't find older pfctl binary, then please try your luck with the one extracted from 12.2-RELEASE install. Best regards, -- Marek Zarychta OpenPGP_signature Description: OpenPGP digital signature

Re: "set skip on lo" on 12.x and 13.0

2021-10-08 Thread Marek Zarychta
W dniu 09.02.2021 o 16:44, Marek Zarychta pisze: > W dniu 09.02.2021 o 15:55, Kristof Provost pisze: >> On 9 Feb 2021, at 15:50, Marek Zarychta wrote: >>> Dear list, >>> >>> I am observing changed behaviour of the rule "set skip on lo". This >>

Re: How to apply brute force rate limitings with rdr and pass rules under FreeBSD 13?

2022-08-25 Thread Marek Zarychta
in on egress inet proto tcp from ! to $internal_server port ... depending on the desired behavior and the complete set of rules. It's also worth mentioning here that PF-specific FreeBSD mailing list exists: freebsd...@freebsd.org Regards, -- Marek Zarychta OpenPGP_signature Description: OpenPGP digital signature

Re: How to apply brute force rate limitings with rdr and pass rules under FreeBSD 13?

2022-08-25 Thread Marek Zarychta
W dniu 25.08.2022 o 11:32, Carlos López Martínez pisze: On 25/08/2022 11:26, Marek Zarychta wrote: W dniu 25.08.2022 o 10:48, Carlos López Martínez pisze: But under Freebsd when I try to combine "pass" with "rdr" rules, it doesn't works. For example: rdr on egress

Re: How to apply brute force rate limitings with rdr and pass rules under FreeBSD 13?

2022-08-25 Thread Marek Zarychta
W dniu 25.08.2022 o 12:06, Carlos López Martínez pisze: On 25/08/2022 11:46, Marek Zarychta wrote: W dniu 25.08.2022 o 11:32, Carlos López Martínez pisze: On 25/08/2022 11:26, Marek Zarychta wrote: W dniu 25.08.2022 o 10:48, Carlos López Martínez pisze: But under Freebsd when I try to

Re: logging NAT sessions (connection tracking)

2022-10-25 Thread Marek Zarychta
for sharing your work with list subscribes. Have you tried to upstream these patches? -- Marek Zarychta OpenPGP_signature Description: OpenPGP digital signature

heads up: IPFW + dummynet and PF in 14.0 and later

2024-03-01 Thread Marek Zarychta
d is that "burst" keyword was rejected when configuring the pipes. Cheers -- Marek Zarychta