Page MenuHomeFreeBSD

pf: allow states to be killed by their pre-NAT address
ClosedPublic

Authored by kp on Oct 20 2023, 8:45 AM.
Tags
None
Referenced Files
F159548464: D42312.id129144.diff
Mon, Jun 15, 2:58 PM
F159541086: D42312.diff
Mon, Jun 15, 1:08 PM
Unknown Object (File)
Sat, Jun 13, 5:10 PM
Unknown Object (File)
May 16 2026, 12:01 AM
Unknown Object (File)
May 16 2026, 12:01 AM
Unknown Object (File)
May 16 2026, 12:00 AM
Unknown Object (File)
Apr 30 2026, 9:54 PM
Unknown Object (File)
Apr 28 2026, 3:13 PM

Details

Summary

If a connection is NAT-ed we could previously only terminate it by its
ID or the post-NAT IP address. Allow users to specify they want look for
the state by its pre-NAT address. Usage: pfctl -k nat -k <address>.

See also: https://redmine.pfsense.org/issues/11556
Sponsored by: Rubicon Communications, LLC ("Netgate")

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

This revision was not accepted when it landed; it landed in state Needs Review.Oct 23 2023, 4:42 PM
This revision was automatically updated to reflect the committed changes.