[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Unexpected Behaviour ? pf "quick" in negated ranges



Hi,

I was struggling with a particular pf ruleset, and I discovered this "unexpected behaviour".

Suppose:

   block in from { 192.168.0.0/24, ! 192.168.11.11 } to any

This blocks in everything on 192.168 except 192.168.11.11, as expected.


However, if:

   block in quick from { 192.168.0.0/24, ! 192.168.11.11 } to any

the rule expands o parsing by pfctl to:

   block in quick from 192.168.0.0/24 to any
   block in quick from ! 192.168.11.11 to any

which leads to a highly undesirable result.

Perhaps mention can be made of this in the man pages, or the parser parse this as an error, or the negated range be coded to work with "quick" ??



Victor

_________________________________________________________________
Get 10mb of inbox space with MSN Hotmail Extra Storage http://join.msn.com/?pgmarket=en-sg