Re: pf broken in 7.0-BETA1 ?



Abdullah Ibn Hamad Al-Marri wrote:
----- Original Message ----
From: Andrew Birukov <amb@xxxxxxxxxxx>
To: Ermal Luçi <ermal.luci@xxxxxxxxx>
Cc: freebsd-stable@xxxxxxxxxxx; freebsd-pf@xxxxxxxxxxx
Sent: Sunday, October 28, 2007 10:34:56 PM
Subject: Re: pf broken in 7.0-BETA1 ?

Ermal Luçi wrote:
Try using

pass out on $ext_if proto tcp from any to any tos 0x10 no keep
state

queue ssh
and it should work as you expect!
pf.conf
-------------------------------------------------------------------
ext_if="xl0"

altq on $ext_if priq bandwidth 520Kb queue { ssh, traf }
queue ssh priority 1
queue traf priority 15 priq(default)

pass in all
pass out all

pass out on $ext_if proto tcp from any to any tos 0x10 no keep state queue ssh
-------------------------------------------------------------------

# /etc/rc.d/pf restart
Disabling pf.
pf disabled
Enabling pf.
/etc/pf.conf:10: syntax error
pfctl: Syntax error in config file: pf rules not loaded
pf enabled

Unfortunately syntax error...


--
Andrew Biriukov
amb@xxxxxxxxxxx


Is this related to your problem?

http://www.nabble.com/Suggestion-with-patch%2C-change-PF-TOS-matching-to-bitmask-tf4697797.html
It is not related, but interesting for me.
I am going to try this patch.
Thank you!

--
Andrew Biriukov
amb@xxxxxxxxxxx
_______________________________________________
freebsd-stable@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-stable
To unsubscribe, send any mail to "freebsd-stable-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: pf broken in 7.0-BETA1 ?
    ... queue ssh priority 1 ... pass out on $ext_if proto tcp from any to any tos 0x10 no keep state ... Mail has the best spam protection around ...
    (freebsd-stable)
  • Re: pf broken in 7.0-BETA1 ?
    ... pass out on $ext_if proto tcp from any to any tos 0x10 no keep state queue ssh ...
    (freebsd-stable)
  • Re: pf broken in 7.0-BETA1 ?
    ... pass out on $ext_if proto tcp from any to any tos 0x10 no keep state queue ... queue ssh priority 1 ... pfctl: Syntax error in config file: pf rules not loaded ...
    (freebsd-stable)
  • Re: pf broken in 7.0-BETA1 ?
    ... pass out on $ext_if proto tcp from any to any tos 0x10 no keep state queue ssh ...
    (freebsd-stable)