From owner-freebsd-pf@FreeBSD.ORG Fri Dec 19 11:10:35 2014 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 2EEE299E for ; Fri, 19 Dec 2014 11:10:35 +0000 (UTC) Received: from smtp.lamaiziere.net (net.lamaiziere.net [37.59.62.186]) by mx1.freebsd.org (Postfix) with ESMTP id E3EBF214F for ; Fri, 19 Dec 2014 11:10:34 +0000 (UTC) Received: from mr185083.univ-rennes1.fr (mr185083.univ-rennes1.fr [129.20.185.83]) by smtp.lamaiziere.net (Postfix) with ESMTPA id 4B1796F52 for ; Fri, 19 Dec 2014 12:01:52 +0100 (CET) Received: from mr185083 (localhost [127.0.0.1]) by mr185083.univ-rennes1.fr (Postfix) with ESMTP id B9285A40 for ; Wed, 17 Dec 2014 15:11:27 +0100 (CET) Date: Wed, 17 Dec 2014 15:11:27 +0100 From: Patrick Lamaiziere To: freebsd-pf@freebsd.org Subject: Re: Getting tables to work in PF Message-ID: <20141217151127.69671d4a@mr185083> In-Reply-To: References: X-Mailer: Claws Mail 3.11.1 (GTK+ 2.24.25; amd64-portbld-freebsd10.0) MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 8bit X-Greylist: Sender succeeded SMTP AUTH, not delayed by milter-greylist-4.4.3 (smtp.lamaiziere.net [0.0.0.0]); Fri, 19 Dec 2014 12:01:52 +0100 (CET) X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 19 Dec 2014 11:10:35 -0000 Le Mon, 3 Nov 2014 23:12:52 +0000, David DeSimone a écrit : Hello, > set skip on lo > > I'm pretty sure the loopback name should be "lo0" instead of just > "lo". Yes and no, the grammar (pf.conf) set skip on ifspec = ( [ "!" ] ( interface-name | interface-group ) ) | "{" interface-list "}" and lo is a valid interface group. So it should work. But you are right because "set skip" does not allow interface groups, this is a bug fixed in recent OpenBSD pf. Regards,