Re: Understanding if-bound vs floating state policy

Igor Podlesny <[email protected]> Sat, 14 Dec 2019 17:11:49 +0700
Newsgroups gmane.os.openbsd.pf
Message-ID <CACdsUq6ZzEDaSzVwePHdB28wywoiNxX-t+dWWOOLeP5nVjegBQ@mail.gmail.com>
[...]
>     to be honest I don't know at top of my head, what is a good/typical
>     use-case for if-bound state policy. I assume those set-ups must be
>     rare/special.

anti-spoofing.

In case one suspects a spoofing attack can be carried out on some "side" network
interface(s), leveraging if-bound state option allows to eliminate the threat.

An example: https://www.openwall.com/lists/oss-security/2019/12/05/1

-- 
End of message. Next message?