pf match ipv6 interface ID
Sonic <[email protected]> Mon, 29 Jun 2026 09:33:34 -0400
| Newsgroups | gmane.os.openbsd.misc |
|---|---|
| Message-ID | <CAP5+4qfWhOM1JS+C5ua07ZHNnhdmnyt5YROQSfrSQsWaRq8hmQ@mail.gmail.com> |
Is it possible to write pf pass/block rules that match the ipv6 interface ID and ignore the prefix (a wildcard prefix if that makes sense)? As my ISP's assigned prefix is not static/stable, and my systems always create the same IID when using SLAAC, it would really be helpful to have this feature for ipv6 firewalling. Thank you, Chris