Re: Understanding if-bound vs floating state policy
Victor Sudakov <[email protected]> Sun, 15 Dec 2019 12:07:04 +0700
| Newsgroups | gmane.os.openbsd.pf |
|---|---|
| Message-ID | <[email protected]> |
Alexandr Nedvedicky wrote: > > > > I see now. The state-policy=floating mislead me into believing that the > > state table was global. Thank you for explaining. > > > > But then, what is the real difference betwttn if-bound and global? > > > > assuming we talk about if-bound vs. floating state policy. > > you have to note the packet direction and interface as two different > attributes to match. > > If you enable if-bound state match policy then PF continues to > check for direction where packet is traveling (@inbounc vs. @outbound), > furthermore PF also requires the packet to be seen on the interface, > where PF saw packet, which has created the state. > > floating relaxes the requirement such interface is omitted, think of packet > may match any/all interfaces, but must travel in expected direction. > > to be honest I don't know at top of my head, what is a good/typical > use-case for if-bound state policy. I assume those set-ups must be > rare/special. Maybe to emulate the Cisco reflexive ACL behaviour? Frankly I'd like to see yet another state-policy, could be called "global" if you wish, which emulates ipfw/ipf bidirectional state behavior. -- Victor Sudakov, VAS4-RIPE, VAS47-RIPN 2:5005/49@fidonet http://vas.tomsk.ru/