.:[ a broken lcd ]:.

Just another console cowboy.
GnuPG Key ID: 0x18B4AA48
main site

Emails:
isomk .:[ at ]:. kyle isom net
brokenlcd .:[ at ]:. google mail

brokenLCD Labs: AVR

This blog is mostly tech rantings. If you know me, subscribe to my other blog for updates on my adventures.
Designed by Redfield. Icons by Cameron Hunt.

pf.conf notes

Text

I just returned to pf after a year (maybe longer) away from it. I had fun returning to pf and getting my soekris running as a router / VPN / blah blah blah. This post is mostly stuff I’ll need to remember in the future if / when I get stuck doing other stuff.

The new scrub rule format is like such:

match in all scrub (options)

Need to remember this.

And as for the NAT rules, here’s an easy starter:

nat on $RED_IF inet from $GREEN_IF:network to any -> ($RED_IF)

As for binat you’re on your own.

Lastly, reassemble tcp tends to screw up ssh on the outbound side (i.e. no match out all scrub (reassemble tcp)) so don’t do it.

That’s all for now.



April 19, 2010, 11:22pm