| Commit message (Collapse) | Author | Age | Files | Lines |
| |
|
|
| |
ok deraadt@
|
| | |
|
| |
|
|
|
|
|
| |
utterly clear this is not a filter criteria but a packet modification thing.
also preparation for upcoming changes, including one to unscrew this mess
(I should not have to touch half the tree for this - ifixitlater)
not user visible, ok gcc
|
| |
|
|
| |
prompted by a mail from Gabriel Linder. OK henning@
|
| | |
|
| |
|
|
|
|
|
|
|
|
|
|
| |
with lots of help from claudio@. Earlier version was ok mikeb@ and looks
good to markus@.
Note: tftp-proxy rdr-to rules must be changed to use divert-to and must
specify the address family.
pass in quick on internal proto udp to port tftp rdr-to 127.0.0.1 port 6969
-changes to-
pass in quick on internal inet proto udp to port tftp divert-to 127.0.0.1 port 6969
|
| |
|
|
|
| |
are not used. bzero() of the rule structure is not enough.
Found with dlg@, OK mcbride@
|
| |
|
|
|
|
|
|
|
|
|
| |
actions. Allow interfaces to be specified in special table entries for
the routing actions. Lists of addresses can now only be done using tables,
which pfctl will generate automatically from the existing syntax.
Functionally, this deprecates the use of multiple tables or dynamic
interfaces in a single nat or rdr rule.
ok henning dlg claudio
|
| |
|
|
|
| |
due to the standard henning+oga commit-and-run-for-beer problem.
ok claudio
|
| |
|
|
| |
ok sthen@
|
| | |
|
| | |
|
| |
|
|
| |
from max laier
|
|
|
ok jolan@, msf@, millert@
man page help from jmc@
|