From owner-freebsd-pf@FreeBSD.ORG Sat Dec 1 07:47:02 2012 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 8959E8EC for ; Sat, 1 Dec 2012 07:47:02 +0000 (UTC) (envelope-from artemrts@ukr.net) Received: from ffe12.ukr.net (ffe12.ukr.net [195.214.192.40]) by mx1.freebsd.org (Postfix) with ESMTP id 308788FC20 for ; Sat, 1 Dec 2012 07:47:02 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=ukr.net; s=ffe; h=Date:Message-Id:From:To:References:In-Reply-To:Subject:Content-Type:Content-Transfer-Encoding:MIME-Version; bh=1ObjkI1Bq62y4zzq63/hVg0FOtT9qCb55UGKId0W/ks=; b=aRaaJ9xGNLjRtxWgE3AY8NYwzJs/EVWBe27HSJTnT3t77195COevrL/l115QnwWRXFVDAbgNBiS/I9naZC1jG+5LFDIELTlJ7i3ZAMvYLlESE9VwKle5RObK3khob+XRDUJMDY+btUDgvz7d2hahQLN8MXpsWhRJINFSHZ1G7ms=; Received: from mail by ffe12.ukr.net with local ID 1TehYD-000Hls-1N for freebsd-pf@freebsd.org; Sat, 01 Dec 2012 09:31:49 +0200 MIME-Version: 1.0 Content-Disposition: inline Content-Transfer-Encoding: binary Content-Type: text/plain; charset="windows-1251" Subject: Re[2]: pfctl -s rules In-Reply-To: <02387299-5EC3-47B7-B1CA-27F36A947D85@my.gd> References: <02387299-5EC3-47B7-B1CA-27F36A947D85@my.gd> <983A61AAA3A744F78601A2488F54CF85@yahoo.com> <9A9FCC5B-CAB2-4EF6-A0FD-2356D9997658@my.gd> <50B8A92C.5090500@yahoo.com.br> <49BF4308335C496593D1D7C82391C805@yahoo.com> <50B8A47E.8060604@yahoo.com.br> To: freebsd-pf@freebsd.org From: "wishmaster" X-Mailer: freemail.ukr.net 4.0 Message-Id: <63585.1354347109.8822055014311788544@ffe12.ukr.net> X-Browser: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:17.0) Gecko/17.0 Firefox/17.0 Date: Sat, 01 Dec 2012 09:31:49 +0200 X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 01 Dec 2012 07:47:02 -0000 > It likely tries to apply rules on an interface that doesn't exist yet (for example openvpn's tun). This issue can avoid by enclose iface's name into parentheses. Like this: pass in quick on tun0 inet proto tcp from any to (tun0) port ...