OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
"keep state" and PF Queues

From: Brian A. Seklecki (lavalampspiritual-machines.org)
Date: Wed Oct 19 2005 - 09:20:31 CDT


Would anyone like to elaborate on the impacts of using "keep state" on
conjunction with pass rules that assign traffic to queues?

One might assume that inverted traffic flows would also be queued, however
that would break the "traffic can only be queued egress an interface"
rule...

There should be some remarks on this in pf.conf(5)

TIA,

         ~BAS