summaryrefslogtreecommitdiff
path: root/share/man/man5/pf.conf.5
AgeCommit message (Collapse)Author
2007-10-14include in bnf, wanted by jmcTheo de Raadt
2007-10-13support an include directive; file of course must also be "secure" likeTheo de Raadt
the main configuration file; ok henning
2007-09-30while rdr'ing port spamd to portsmtpis perfectly valid, it is at leastHenning Brauer
a bit confuzzling, so swap. From: Olli Hauer <ohauer@gmx.de>
2007-09-27Mention "set loginterface <ifgroup>"Marco Pfatschbacher
2007-08-30document address ranges, with help from jmc@Daniel Hartmeier
2007-07-17typo; from Stephan A. RickauerJason McIntyre
2007-06-26checkd -> checked; from Nicholas MarriottJason McIntyre
2007-06-08make it clearer where ifgroups can be usedHenning Brauer
From: Stuart Henderson <stu@spacehopper.org>
2007-05-31convert to new .Dd format;Jason McIntyre
2007-05-08Document the fact that 'allow-opts' applies to IPv6 now as well.Ryan Thomas McBride
ok jmc@ dhartmei@ henning@ deraadt@ claudio@
2007-04-14set timeout source-track -> set timeout src.track; from Jason TestartJason McIntyre
and a missing full stop...
2007-03-21Basic ruleset optimization is now the default.Ryan Thomas McBride
Use 'set ruleset-optimization none' or the -o none argument to prevent pfctl from optimizing the ruleset before loading it.
2006-12-01Correct the explanation of NAT evaluation order. binat is always first,Camiel Dobbelaar
then rdr on inbound packets or nat on outbound packets. This is _not_ necessarily the same order in which the rules are defined in the ruleset. ok jmc dhartmei henning
2006-11-29stateles -> stateless; from stuart hendersonJason McIntyre
2006-11-28bad space;Jason McIntyre
2006-11-28mention rtable shitz now that it is enabled in the forwarding pathHenning Brauer
2006-11-09desireable -> desirable;Jason McIntyre
2006-11-01tweaks;Jason McIntyre
2006-10-31Document set ruleset-optimization [ none | basic | profile ].Ryan Thomas McBride
2006-10-28Document inline anchor loading with { } delimited blocks.Ryan Thomas McBride
2006-10-26tweak;Jason McIntyre
2006-10-26tweaks; ok henningJason McIntyre
2006-10-26eep! unbreak.Ryan Thomas McBride
2006-10-26Document hostid.Ryan Thomas McBride
pointed out by Pierre-Yves Ritschard.
2006-10-25document how ot send logs to alternate pflog interfacesHenning Brauer
2006-10-23remove trailing space;Jason McIntyre
2006-10-22Move the stateful content up to the FILTERING section and flesh it outRyan Thomas McBride
somewhat to reflect the default 'keep state' behaviour of pf.conf. prodding by theo, ok jmc@
2006-10-11fix mark up mistake;Jason McIntyre
2006-10-11Document 'anchor "foo" quick'.Ryan Thomas McBride
2006-10-06these fixes got lost somehow;Jason McIntyre
2006-10-06missing fixes for STATEFUL INSPECTION;Jason McIntyre
2006-10-06kill trailing whitespace;Jason McIntyre
2006-10-06Document the fact that 'flags S/SA keep state' is now the implicit default,Ryan Thomas McBride
as well as 'no state' and 'flags any' options. ok jmc@
2006-09-12for apps which use interface groups, point to the section ofJason McIntyre
ifconfig(8) where they are explained; ok mcbride mpf henning
2006-08-31knock out the cpp/m4 stuff from MACROS; after discussion with many...Jason McIntyre
2006-08-22back out -r1.497 (support for "tagged {}" lists), it broke "tagged" supportDaniel Hartmeier
for nat rules. sorry, existing functionality trumps syntactic sugar. feel free to resubmit a complete patch. closes PR 5207.
2006-08-02in the BNF section, note that a comma is optional, closes PR 5191Daniel Hartmeier
2006-07-25document "tos": pointed out by maxim bourmistrovJason McIntyre
diff from jared r r spiegel ok dhartmei
2006-07-09The timeout value is called src.track, not source-track.Ryan Thomas McBride
2006-06-18typo: queu -> queueHans-Joerg Hoexer
ok claudio@
2006-05-28put previous in the correct place; ok mcbrideJason McIntyre
2006-05-28Adaptive timeouts are now on by default.Ryan Thomas McBride
2006-05-14interface bandwidths can change; ok henningTheo de Raadt
2006-05-01update the "tagged" line; ok dhartmeiJason McIntyre
2006-05-01add support for "tagged {}" lists, from Pierre-Yves RitschardDaniel Hartmeier
2006-04-30- replace <> with .AqJason McIntyre
- replace OpenBSD with .Ox from wiz@netbsd
2006-03-14implement a Unicast Reverse Path Forwarding (uRPF) check for pf(4)Damien Miller
which optionally verifies that a packet is received on the interface that holds the route back to the packet's source address. This makes it an automatic ingress filter, but only when routing is fully symmetric. bugfix feedback claudio@; ok claudio@ and dhartmei@
2006-02-20new ftp-proxyCamiel Dobbelaar
ok jmc markus
2006-01-18Document the "tables" and "table-entries" limit options.Joel Knight
ok jmc@ mcbride@
2005-11-17document "log (user)"Joel Knight
wording help and ok jmc@