Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 05 Dec 2008 11:23:28 +0300
From:      Vladimir Ermakov <samflanker@gmail.com>
To:        Max Laier <max@love2party.net>
Cc:        freebsd-pf@freebsd.org
Subject:   Re: synproxy state does not work on FreeBSD 7.1-PRERELEASE
Message-ID:  <4938E500.9090805@gmail.com>
In-Reply-To: <200812041828.34033.max@love2party.net>
References:  <4937F627.8080602@gmail.com> <200812041647.14049.max@love2party.net> <200812041828.34033.max@love2party.net>

next in thread | previous in thread | raw e-mail | index | archive | help
Max Laier wrote:
> On Thursday 04 December 2008 16:47:13 Max Laier wrote:
>   
>> On Thursday 04 December 2008 16:24:23 Vladimir Ermakov wrote:
>>     
>>> problem is fixed in OpenBSD 4.4
>>> http://www.openbsd.org/plus44.html
>>>       
>> The bug this note refers to was introduced after OpenBSD 4.1 (our last
>> import) and should not be present in the FreeBSD code.  I'll double check
>> in a bit to make sure synproxy is working, but I don't think it was broken
>> after my last import ... do you have a particular test case that I could
>> reproduce?
>>     
>
> Okay ... here is the story:  First off, "synproxy state" is *NOT* broken!  But 
> you need to be careful how you use it.  If you - like the OP - intend to use 
> it to protect a service running on the same box as your pf, you must make sure 
> to "set skip on lo0" or it will not work.  If you are protecting a box behind 
> the pf box, there is no need for that.
>
>   
Can a `synproxy state` to work on the CARP interface?

/Vladimir Ermakov





Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4938E500.9090805>