[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: pf packet filter OpenBSD 3.2



Hello,

on misc_(_at_)_openbsd_(_dot_)_org, Henning Brauer wrote:
> On Tue, Jan 28, 2003 at 03:05:56PM +0300, Katasonov Sergey wrote:
>> Cool. Is there a way to reference all interface network? i.e. interface ip
>> with applied netmask?
> 
> the code is there - check ifa_looup() in pfctl_parser.c (in -current, in
> -stable it lives in parse.y).
> though, I didn't have a good idea for the syntax yet.
> net(dc0)?
this would introduce function-like constructs, does not feel good to
me.

> dc0-net?
only useful if "-" is definitely disallowed in device names

> certainly not dc0:net, that is a PITA.
totally. If I did not know better I would think this is a port
number.

Have you thought about brackets? [dc0] kind of jumped into my mind.

Ciao, Arne.
-- 
 ,``o. OpenBSD        -        Debian GNU/Linux        -        Solaris  >o)
>( ,c@ GPG 1024D/913C2F81 2000-10-11  Arne P. Boettger <apb_(_at_)_createx_(_dot_)_de>  /\\
 ',,,' Fingerprint = 6ED9 9A64 CD8A EB6F D841  0391 2F08 8F86 913C 2F81 _\_V