[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
Re: Source-based routing (sometimes)
On Tue, Nov 24, 2009 at 06:54:51PM +0100, Hans Rosenfeld wrote:
> On Tue, Nov 24, 2009 at 10:59:01AM -0600, Michael Graff wrote:
> > I tried adding this to my pf.conf:
> > pass out on rtk0 route-to ( gif0 220.127.116.11 ) from 18.104.22.168/24 to
> > any
> > It seems that the route-to is ignored.
> I recently had a similar problem. Some other pf rule created state
> information that matched those packets that were supposed to go through
> the tunnel. Adding "no state" to all rules that could possibly affect
> those packets fixed it for me.
Just in case you need to create state, you can bind state to an
interface with the keyword 'if-bound'. That will let PF filter process
the packet a second time on a second interface.
David Young OJC Technologies
dyoung%ojctech.com@localhost Urbana, IL * (217) 278-3933
Main Index |
Thread Index |