Unix Technical Forum

Untitled

This is a discussion on Untitled within the mailing.openbsd.tech forums, part of the OpenBSD category; --> In our situation pfsync has a syncif of fxp1, our internal network gateway interface. In trying to shutdown pfsync ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > mailing.openbsd.tech

Register FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-18-2008, 06:55 AM
fury@nexxus.net
 
Posts: n/a
Default Untitled

In our situation pfsync has a syncif of fxp1, our internal network
gateway interface.

In trying to shutdown pfsync from broadcasting state changes to a non
existant recipient machine we tried the following:

ifconfig pfsync0 down

No effect, but the virtual interface pfsync is down. It was a while before
we realized that since the sync interface is fxp1, and we are explicitly
allowing pfsync traffic on this interface, that state will continue to be
broadcast over fxp1.

We changed pf.conf to block pfsync traffic on fxp1 and it no longer
broadcasts.

Now. I am curious, what is the best way to disable pfsync from
broadcasting on the sync interface without changing the firewall ruleset?

I am thinking: ifconfig destroy pfsync0

Would this uncouple the binding to the sync interface?

Thanks in advance,
Rich

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 09:43 PM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com