On Fri, Dec 04, 2020 at 01:08:53AM +0100, Alexandr Nedvedicky wrote: > below is updated diff. The new diff also updates pf.conf(5) manpage.
OK bluhm@ A note for the man page. > @@ -2126,6 +2126,9 @@ will not work if > .Xr pf 4 > operates on a > .Xr bridge 4 . > +Also > +.Cm synproxy state > +option acts on inbound packets only. The synproxy rules are the subject of the previous sentence. I would not repeate synproxy state in one paragraph. What about Also they act on incoming SYN packets only.