Re: packets to bridged interfaces bypass input filter

2020-06-17 Thread Sven M . Hallberg
Stephan Mending on Wed, May 27 2020: >> [bridge0 with members athn0 em0 vether0, all in group lan] >> >> # ifconfig athn0 -group lan > Did you flush states between your tests (pfctl -F states) ? -> After > you removed athn0 from lan group ? Yes, I did. >> [sys/net/if_bridge.c: bridge_pro

Re: packets to bridged interfaces bypass input filter

2020-05-26 Thread Stephan Mending
On Tue, May 26, 2020 at 09:26:07PM +0200, Sven M. Hallberg wrote: > hi all, > > i sent the following question to misc@ on march 29th but received no > response. i hope you don't mind me retrying on tech@. > > while playing around with pf, i noticed that some connections that i > thought should be

packets to bridged interfaces bypass input filter

2020-05-26 Thread Sven M. Hallberg
hi all, i sent the following question to misc@ on march 29th but received no response. i hope you don't mind me retrying on tech@. while playing around with pf, i noticed that some connections that i thought should be blocked, were in fact not. here is my fairly standard bridge setup between a wl