From ef67ad380fb6a17c69ddfe6409751cee1ae008e9 Mon Sep 17 00:00:00 2001 From: henning <> Date: Tue, 23 Aug 2005 02:52:58 +0000 Subject: [PATCH] replace the "pass quick" example line for loopback and the inner interface with a set skip statement to the same effect, performs way better suggested by Stuart Henderson , theo ok --- src/etc/pf.conf | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/src/etc/pf.conf b/src/etc/pf.conf index 7a0a3708..9fc7bb75 100644 --- a/src/etc/pf.conf +++ b/src/etc/pf.conf @@ -1,4 +1,4 @@ -# $OpenBSD: pf.conf,v 1.28 2004/04/29 21:03:09 frantzen Exp $ +# $OpenBSD: pf.conf,v 1.29 2005/08/23 02:52:58 henning Exp $ # # See pf.conf(5) and /usr/share/pf for syntax and examples. # Remember to set net.inet.ip.forwarding=1 and/or net.inet6.ip6.forwarding=1 @@ -10,6 +10,8 @@ #table persist #table persist +#set skip on { lo $int_if } + #scrub in #nat on $ext_if from !($ext_if) -> ($ext_if:0) @@ -22,7 +24,6 @@ #block in #pass out keep state -#pass quick on { lo $int_if } #antispoof quick for { lo $int_if } #pass in on $ext_if proto tcp to ($ext_if) port ssh keep state