Re: Understanding if-bound vs floating state policy

Victor Sudakov <[email protected]> Sun, 15 Dec 2019 12:07:04 +0700
Newsgroups gmane.os.openbsd.pf
Message-ID <[email protected]>
Alexandr Nedvedicky wrote:
> > 
> > I see now. The state-policy=floating mislead me into believing that the 
> > state table was global. Thank you for explaining.
> > 
> > But then, what is the real difference betwttn if-bound and global?
> > 
> 
>     assuming we talk about if-bound vs. floating state policy. 
> 
>     you have to note the packet direction and interface as two different
>     attributes to match.
> 
>     If you enable if-bound state match policy then PF continues to
>     check for direction where packet is traveling (@inbounc vs. @outbound),
>     furthermore PF also requires the packet to be seen on the interface,
>     where PF saw packet, which has created the state.
> 
>     floating relaxes the requirement such interface is omitted, think of packet
>     may match any/all interfaces, but must travel in expected direction.
> 
>     to be honest I don't know at top of my head, what is a good/typical
>     use-case for if-bound state policy. I assume those set-ups must be
>     rare/special.

Maybe to emulate the Cisco reflexive ACL behaviour?

Frankly I'd like to see yet another state-policy, could be called
"global" if you wish, which emulates ipfw/ipf bidirectional state behavior.

-- 
Victor Sudakov,  VAS4-RIPE, VAS47-RIPN
2:5005/49@fidonet http://vas.tomsk.ru/