Hi,
Consider this very simple PF configuration, on a multi-NIC machine but with only bge0 as active (others are even not connected):
When on sparc64 and starting the PF service using
This does not happen with the very same rules and the same bge driver with a 10.0-RELEASE/i386 machine.
Any hint ?
Consider this very simple PF configuration, on a multi-NIC machine but with only bge0 as active (others are even not connected):
Code:
set block-policy return
set skip on lo0
block all
pass in on bge0
pass out on bge0
service pf start
, ie (/sbin/pfctl -F all; /sbin/pfctl -f /etc/pf.conf; /sbin/pfctl -eq)
, existing TCP connexions are reset. The block-policy statement only helps to face the Reset immediately, but it also occurs without it. This does not happen with the very same rules and the same bge driver with a 10.0-RELEASE/i386 machine.
Any hint ?