Wednesday, September 26, 2018

Interface modifiers in pf.conf

Hi

I can in the man page för PF see:

--snip--
Interface names, interface group names, and self can have
modifiers appended:

:0 Do not include interface aliases.
:broadcast Translates to the interface's broadcast address(es).
:network Translates to the network(s) attached to the
interface.
:peer Translates to the point-to-point interface's peer
address(es).
--snip--

Is there a special reason syntax like INTERNET_INT:1 wont work if we want to use the first alias address from the hostname interface file?

As it is now I have to use the base adress by using ":0" or including all aliases. For me this seems unusable. If I want to nat out on the alias address from for example the DMZ I would like to use ":1". As this is not possible I have to hard code the IP:s in pf.conf.


Have I misunderstood something? Please enlighten me.


Tnx
Peo

No comments:

Post a Comment