claudio
557ed03945
Extend the initial pf ruleset to explicitly allow dhcp / bootp and dhcpv6.
Our dhclient only uses the bpf tap for broadcast packets (which bypass pf) but lease renewals will use a regular socket and are blocked without this change. Rules are written so that accidential forwarding of packets is not possible. Diff from brad@, OK henning@, benno@, mikeb@ |
10 years ago | |
---|---|---|
src | Extend the initial pf ruleset to explicitly allow dhcp / bootp and dhcpv6. | 10 years ago |