[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
Re: kern/48377: pf "synproxy state" hangs connections to local services
The following reply was made to PR kern/48377; it has been noted by GNATS.
From: "John D. Baker" <jdbaker%mylinuxisp.com@localhost>
Subject: Re: kern/48377: pf "synproxy state" hangs connections to local
Date: Thu, 15 Jan 2015 09:43:44 -0600 (CST)
After some thought and reading 'pf' documentation, particularly the
cautions about redirecting services to the default loopback address,
I realized another solution.
Define another looback interface, say "lo1", with an appropriate non-
routable address (RFC1918) and redirect incoming connections for local
services to this interface/address.
Make sure local services bind either to a wildcard interface/address
or specifically the "dummy" loopback interface/address.
Filter rules can then use "synproxy state".
|/"\ John D. Baker, KN5UKS NetBSD Darwin/MacOS X
|\ / jdbaker[snail]mylinuxisp[flyspeck]com OpenBSD FreeBSD
| X No HTML/proprietary data in email. BSD just sits there and works!
|/ \ GPGkeyID: D703 4A7E 479F 63F8 D3F4 BD99 9572 8F23 E4AD 1645
Main Index |
Thread Index |