[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

pf rules and if aliases



I have noted that if I add aliases on an interface I need to change some of the filtering rules as well (of course).

What is the proper way to do this, with one ip I used:
ext_if="xl0"
block out log on $ext_if inet from !$ext_if to any

Should I change to:
ext_if="{ xxx.yyy.zzz.001/32, xxx.yyy.zzz.002/32 }

or is there a better way?

Perhaps this is already mentioned somewhere, sorry if I missed it.



Visit your host, monkey.org