History log of /openbsd-current/share/man/man4/pfsync.4
Revision (<<< Hide revision tags) (Show revision tags >>>) Date Author Comments
# 1.39 31-Jan-2024 jmc

the maxupd example was removed in -r.1.15, so do not refer to it;
from janne johansson

with that removal the surrounding text becomes simpler, so trim it;


# 1.38 18-Oct-2023 benno

with pfsync rewrite, pfsync interfaces need an "up" after configuration, not before.
Noted by Marko Cupac, thanks.


Revision tags: OPENBSD_6_9_BASE OPENBSD_7_0_BASE OPENBSD_7_1_BASE OPENBSD_7_2_BASE OPENBSD_7_3_BASE OPENBSD_7_4_BASE
# 1.37 01-Feb-2021 sthen

describe pfsync(4)'s use of carpdemote, ok/tweak kn deraadt


Revision tags: OPENBSD_6_1_BASE OPENBSD_6_2_BASE OPENBSD_6_3_BASE OPENBSD_6_4_BASE OPENBSD_6_5_BASE OPENBSD_6_6_BASE OPENBSD_6_7_BASE OPENBSD_6_8_BASE
# 1.36 30-Aug-2016 jmc

use a mixture of .Dl and .Bd -compact to reduce the amount of
vertical whitespace, making it easier to see which hostname.if file
relates to which example;


# 1.35 29-Aug-2016 mpi

Make examples fit in 80 columns, reminded by jmc@


# 1.34 25-Aug-2016 sthen

Fix pfsync(4)'s carp examples: as of ip_carp.c r1.245, carpdev must be
specified. From Bryan Stenson.


Revision tags: OPENBSD_5_8_BASE OPENBSD_5_9_BASE OPENBSD_6_0_BASE
# 1.33 25-Jun-2015 jmc

pfsync and ipsec do not currently work; from lukasz czarniecki
i've chosen to comment out the pertinent text rather than remove it...

confirmation/ok dlg


Revision tags: OPENBSD_5_7_BASE
# 1.32 01-Feb-2015 jsg

Fix a typo in the Nd line. From Steven McDonald.


Revision tags: OPENBSD_4_8_BASE OPENBSD_4_9_BASE OPENBSD_5_0_BASE OPENBSD_5_1_BASE OPENBSD_5_2_BASE OPENBSD_5_3_BASE OPENBSD_5_4_BASE OPENBSD_5_5_BASE OPENBSD_5_6_BASE
# 1.31 29-Apr-2010 henning

fix multicast address, Sebastian Benoit <benoit-lists at fb12.de>


Revision tags: OPENBSD_4_7_BASE
# 1.30 27-Nov-2009 jmc

benefical -> beneficial; from Brad Tilley


Revision tags: OPENBSD_4_6_BASE
# 1.29 17-Jun-2009 sthen

Document the 'defer' ifconfig flag. From me with a few tweaks by dlg@.
reads ok to jmc@.


Revision tags: OPENBSD_4_5_BASE
# 1.28 17-Feb-2009 dlg

massage a bit. note that pfsync in openbsd 4.4 and 4.5 are incompatible.

requested by deraadt@ tweaks by jmc@


Revision tags: OPENBSD_4_4_BASE
# 1.27 03-Jun-2008 jmc

fix some spacing issues;


Revision tags: OPENBSD_4_3_BASE
# 1.26 20-Sep-2007 mpf

Since keep state is the default now, change pf.conf
example to use (no-sync) for pfsync and carp traffic.
OK mcbride@


Revision tags: OPENBSD_4_2_BASE
# 1.25 31-May-2007 jmc

convert to new .Dd format;


Revision tags: OPENBSD_4_1_BASE
# 1.24 23-Oct-2006 jmc

no need to use "keep state" and "flags S/SA" in pf rules,
now that it is the default;

ok henning mcbride camield (ftp-proxy bits) deraadt


Revision tags: OPENBSD_3_8_BASE OPENBSD_3_9_BASE OPENBSD_4_0_BASE
# 1.23 09-Aug-2005 jmc

add Xr to ifstated(8);
ok mpf@


Revision tags: OPENBSD_3_7_BASE
# 1.22 24-Feb-2005 jmc

add carp(4) to SEE ALSO;
from freebsd -r1.4;


# 1.21 06-Feb-2005 mcbride

missing words


# 1.20 20-Jan-2005 mcbride

Document syncif->syncdev change. Also fix order of syncdev option
in ifconfig manpage.


Revision tags: OPENBSD_3_6_BASE
# 1.19 03-Aug-2004 jmc

tweaks;


# 1.18 03-Aug-2004 mcbride

Document 'syncpeer'.


# 1.17 31-Mar-2004 jmc

a little cleanup;


Revision tags: OPENBSD_3_5_BASE
# 1.16 22-Mar-2004 jmc

some spacing, and a little cleanup;
ok deraadt@


# 1.15 22-Mar-2004 mcbride

Add a complete pfsync+carp firewall failover example.

ok deraadt@


# 1.14 21-Mar-2004 miod

Homogeneize config lines for pseudo-devices, and do not put fixed values.


# 1.13 13-Mar-2004 jmc

typos from Lawrence Teo;


# 1.12 24-Dec-2003 mcbride

Update protocol number and multicast group to match reality.

Pointed out by Jorge Severino (jorge at netsecure dot cl)


# 1.11 16-Dec-2003 jmc

pfsync.4:
- new sentence, new line
- kill whitespace at EOL
- escape a dot at EOL

pflog.4:
- subject verb agreement


# 1.10 16-Dec-2003 mcbride

Reorg and better english. Split network synchronisation specifics
into it's own section.


# 1.9 16-Dec-2003 mcbride

1st pass at documenting the new pfsync network synchronisation
functionality.

ok deraadt@


# 1.8 08-Nov-2003 jmc

- ommited -> omitted
- kill some whitespace at EOL
- remove unnecessary args to .Nm


# 1.7 08-Nov-2003 mcbride

Add 'no-sync' state option to prevent state transition messages for states
created by this rule from appearing on the pfsync(4) interface. e.g.

pass in proto tcp to self flags S/SA keep state (no-sync)

ok cedric@ henning@ dhartmei@


Revision tags: OPENBSD_3_4_BASE
# 1.6 06-Jun-2003 jmc

- section reorder
- some macro fixes
- kill whitespace at EOL


# 1.5 01-Apr-2003 mickey

there could be only one


# 1.4 31-Mar-2003 mpech

pfsync interface may need an argument in kernel config like pflog(4).

henning@ ok


Revision tags: OPENBSD_3_3_BASE
# 1.3 30-Nov-2002 mickey

dead e


# 1.2 29-Nov-2002 henning

wording


# 1.1 29-Nov-2002 mickey

das ist pfsync.4


# 1.38 18-Oct-2023 benno

with pfsync rewrite, pfsync interfaces need an "up" after configuration, not before.
Noted by Marko Cupac, thanks.


Revision tags: OPENBSD_6_9_BASE OPENBSD_7_0_BASE OPENBSD_7_1_BASE OPENBSD_7_2_BASE OPENBSD_7_3_BASE OPENBSD_7_4_BASE
# 1.37 01-Feb-2021 sthen

describe pfsync(4)'s use of carpdemote, ok/tweak kn deraadt


Revision tags: OPENBSD_6_1_BASE OPENBSD_6_2_BASE OPENBSD_6_3_BASE OPENBSD_6_4_BASE OPENBSD_6_5_BASE OPENBSD_6_6_BASE OPENBSD_6_7_BASE OPENBSD_6_8_BASE
# 1.36 30-Aug-2016 jmc

use a mixture of .Dl and .Bd -compact to reduce the amount of
vertical whitespace, making it easier to see which hostname.if file
relates to which example;


# 1.35 29-Aug-2016 mpi

Make examples fit in 80 columns, reminded by jmc@


# 1.34 25-Aug-2016 sthen

Fix pfsync(4)'s carp examples: as of ip_carp.c r1.245, carpdev must be
specified. From Bryan Stenson.


Revision tags: OPENBSD_5_8_BASE OPENBSD_5_9_BASE OPENBSD_6_0_BASE
# 1.33 25-Jun-2015 jmc

pfsync and ipsec do not currently work; from lukasz czarniecki
i've chosen to comment out the pertinent text rather than remove it...

confirmation/ok dlg


Revision tags: OPENBSD_5_7_BASE
# 1.32 01-Feb-2015 jsg

Fix a typo in the Nd line. From Steven McDonald.


Revision tags: OPENBSD_4_8_BASE OPENBSD_4_9_BASE OPENBSD_5_0_BASE OPENBSD_5_1_BASE OPENBSD_5_2_BASE OPENBSD_5_3_BASE OPENBSD_5_4_BASE OPENBSD_5_5_BASE OPENBSD_5_6_BASE
# 1.31 29-Apr-2010 henning

fix multicast address, Sebastian Benoit <benoit-lists at fb12.de>


Revision tags: OPENBSD_4_7_BASE
# 1.30 27-Nov-2009 jmc

benefical -> beneficial; from Brad Tilley


Revision tags: OPENBSD_4_6_BASE
# 1.29 17-Jun-2009 sthen

Document the 'defer' ifconfig flag. From me with a few tweaks by dlg@.
reads ok to jmc@.


Revision tags: OPENBSD_4_5_BASE
# 1.28 17-Feb-2009 dlg

massage a bit. note that pfsync in openbsd 4.4 and 4.5 are incompatible.

requested by deraadt@ tweaks by jmc@


Revision tags: OPENBSD_4_4_BASE
# 1.27 03-Jun-2008 jmc

fix some spacing issues;


Revision tags: OPENBSD_4_3_BASE
# 1.26 20-Sep-2007 mpf

Since keep state is the default now, change pf.conf
example to use (no-sync) for pfsync and carp traffic.
OK mcbride@


Revision tags: OPENBSD_4_2_BASE
# 1.25 31-May-2007 jmc

convert to new .Dd format;


Revision tags: OPENBSD_4_1_BASE
# 1.24 23-Oct-2006 jmc

no need to use "keep state" and "flags S/SA" in pf rules,
now that it is the default;

ok henning mcbride camield (ftp-proxy bits) deraadt


Revision tags: OPENBSD_3_8_BASE OPENBSD_3_9_BASE OPENBSD_4_0_BASE
# 1.23 09-Aug-2005 jmc

add Xr to ifstated(8);
ok mpf@


Revision tags: OPENBSD_3_7_BASE
# 1.22 24-Feb-2005 jmc

add carp(4) to SEE ALSO;
from freebsd -r1.4;


# 1.21 06-Feb-2005 mcbride

missing words


# 1.20 20-Jan-2005 mcbride

Document syncif->syncdev change. Also fix order of syncdev option
in ifconfig manpage.


Revision tags: OPENBSD_3_6_BASE
# 1.19 03-Aug-2004 jmc

tweaks;


# 1.18 03-Aug-2004 mcbride

Document 'syncpeer'.


# 1.17 31-Mar-2004 jmc

a little cleanup;


Revision tags: OPENBSD_3_5_BASE
# 1.16 22-Mar-2004 jmc

some spacing, and a little cleanup;
ok deraadt@


# 1.15 22-Mar-2004 mcbride

Add a complete pfsync+carp firewall failover example.

ok deraadt@


# 1.14 21-Mar-2004 miod

Homogeneize config lines for pseudo-devices, and do not put fixed values.


# 1.13 13-Mar-2004 jmc

typos from Lawrence Teo;


# 1.12 24-Dec-2003 mcbride

Update protocol number and multicast group to match reality.

Pointed out by Jorge Severino (jorge at netsecure dot cl)


# 1.11 16-Dec-2003 jmc

pfsync.4:
- new sentence, new line
- kill whitespace at EOL
- escape a dot at EOL

pflog.4:
- subject verb agreement


# 1.10 16-Dec-2003 mcbride

Reorg and better english. Split network synchronisation specifics
into it's own section.


# 1.9 16-Dec-2003 mcbride

1st pass at documenting the new pfsync network synchronisation
functionality.

ok deraadt@


# 1.8 08-Nov-2003 jmc

- ommited -> omitted
- kill some whitespace at EOL
- remove unnecessary args to .Nm


# 1.7 08-Nov-2003 mcbride

Add 'no-sync' state option to prevent state transition messages for states
created by this rule from appearing on the pfsync(4) interface. e.g.

pass in proto tcp to self flags S/SA keep state (no-sync)

ok cedric@ henning@ dhartmei@


Revision tags: OPENBSD_3_4_BASE
# 1.6 06-Jun-2003 jmc

- section reorder
- some macro fixes
- kill whitespace at EOL


# 1.5 01-Apr-2003 mickey

there could be only one


# 1.4 31-Mar-2003 mpech

pfsync interface may need an argument in kernel config like pflog(4).

henning@ ok


Revision tags: OPENBSD_3_3_BASE
# 1.3 30-Nov-2002 mickey

dead e


# 1.2 29-Nov-2002 henning

wording


# 1.1 29-Nov-2002 mickey

das ist pfsync.4


# 1.37 01-Feb-2021 sthen

describe pfsync(4)'s use of carpdemote, ok/tweak kn deraadt


Revision tags: OPENBSD_6_1_BASE OPENBSD_6_2_BASE OPENBSD_6_3_BASE OPENBSD_6_4_BASE OPENBSD_6_5_BASE OPENBSD_6_6_BASE OPENBSD_6_7_BASE OPENBSD_6_8_BASE
# 1.36 30-Aug-2016 jmc

use a mixture of .Dl and .Bd -compact to reduce the amount of
vertical whitespace, making it easier to see which hostname.if file
relates to which example;


# 1.35 29-Aug-2016 mpi

Make examples fit in 80 columns, reminded by jmc@


# 1.34 25-Aug-2016 sthen

Fix pfsync(4)'s carp examples: as of ip_carp.c r1.245, carpdev must be
specified. From Bryan Stenson.


Revision tags: OPENBSD_5_8_BASE OPENBSD_5_9_BASE OPENBSD_6_0_BASE
# 1.33 25-Jun-2015 jmc

pfsync and ipsec do not currently work; from lukasz czarniecki
i've chosen to comment out the pertinent text rather than remove it...

confirmation/ok dlg


Revision tags: OPENBSD_5_7_BASE
# 1.32 01-Feb-2015 jsg

Fix a typo in the Nd line. From Steven McDonald.


Revision tags: OPENBSD_4_8_BASE OPENBSD_4_9_BASE OPENBSD_5_0_BASE OPENBSD_5_1_BASE OPENBSD_5_2_BASE OPENBSD_5_3_BASE OPENBSD_5_4_BASE OPENBSD_5_5_BASE OPENBSD_5_6_BASE
# 1.31 29-Apr-2010 henning

fix multicast address, Sebastian Benoit <benoit-lists at fb12.de>


Revision tags: OPENBSD_4_7_BASE
# 1.30 27-Nov-2009 jmc

benefical -> beneficial; from Brad Tilley


Revision tags: OPENBSD_4_6_BASE
# 1.29 17-Jun-2009 sthen

Document the 'defer' ifconfig flag. From me with a few tweaks by dlg@.
reads ok to jmc@.


Revision tags: OPENBSD_4_5_BASE
# 1.28 17-Feb-2009 dlg

massage a bit. note that pfsync in openbsd 4.4 and 4.5 are incompatible.

requested by deraadt@ tweaks by jmc@


Revision tags: OPENBSD_4_4_BASE
# 1.27 03-Jun-2008 jmc

fix some spacing issues;


Revision tags: OPENBSD_4_3_BASE
# 1.26 20-Sep-2007 mpf

Since keep state is the default now, change pf.conf
example to use (no-sync) for pfsync and carp traffic.
OK mcbride@


Revision tags: OPENBSD_4_2_BASE
# 1.25 31-May-2007 jmc

convert to new .Dd format;


Revision tags: OPENBSD_4_1_BASE
# 1.24 23-Oct-2006 jmc

no need to use "keep state" and "flags S/SA" in pf rules,
now that it is the default;

ok henning mcbride camield (ftp-proxy bits) deraadt


Revision tags: OPENBSD_3_8_BASE OPENBSD_3_9_BASE OPENBSD_4_0_BASE
# 1.23 09-Aug-2005 jmc

add Xr to ifstated(8);
ok mpf@


Revision tags: OPENBSD_3_7_BASE
# 1.22 24-Feb-2005 jmc

add carp(4) to SEE ALSO;
from freebsd -r1.4;


# 1.21 06-Feb-2005 mcbride

missing words


# 1.20 20-Jan-2005 mcbride

Document syncif->syncdev change. Also fix order of syncdev option
in ifconfig manpage.


Revision tags: OPENBSD_3_6_BASE
# 1.19 03-Aug-2004 jmc

tweaks;


# 1.18 03-Aug-2004 mcbride

Document 'syncpeer'.


# 1.17 31-Mar-2004 jmc

a little cleanup;


Revision tags: OPENBSD_3_5_BASE
# 1.16 22-Mar-2004 jmc

some spacing, and a little cleanup;
ok deraadt@


# 1.15 22-Mar-2004 mcbride

Add a complete pfsync+carp firewall failover example.

ok deraadt@


# 1.14 21-Mar-2004 miod

Homogeneize config lines for pseudo-devices, and do not put fixed values.


# 1.13 13-Mar-2004 jmc

typos from Lawrence Teo;


# 1.12 24-Dec-2003 mcbride

Update protocol number and multicast group to match reality.

Pointed out by Jorge Severino (jorge at netsecure dot cl)


# 1.11 16-Dec-2003 jmc

pfsync.4:
- new sentence, new line
- kill whitespace at EOL
- escape a dot at EOL

pflog.4:
- subject verb agreement


# 1.10 16-Dec-2003 mcbride

Reorg and better english. Split network synchronisation specifics
into it's own section.


# 1.9 16-Dec-2003 mcbride

1st pass at documenting the new pfsync network synchronisation
functionality.

ok deraadt@


# 1.8 08-Nov-2003 jmc

- ommited -> omitted
- kill some whitespace at EOL
- remove unnecessary args to .Nm


# 1.7 08-Nov-2003 mcbride

Add 'no-sync' state option to prevent state transition messages for states
created by this rule from appearing on the pfsync(4) interface. e.g.

pass in proto tcp to self flags S/SA keep state (no-sync)

ok cedric@ henning@ dhartmei@


Revision tags: OPENBSD_3_4_BASE
# 1.6 06-Jun-2003 jmc

- section reorder
- some macro fixes
- kill whitespace at EOL


# 1.5 01-Apr-2003 mickey

there could be only one


# 1.4 31-Mar-2003 mpech

pfsync interface may need an argument in kernel config like pflog(4).

henning@ ok


Revision tags: OPENBSD_3_3_BASE
# 1.3 30-Nov-2002 mickey

dead e


# 1.2 29-Nov-2002 henning

wording


# 1.1 29-Nov-2002 mickey

das ist pfsync.4


Revision tags: OPENBSD_6_1_BASE OPENBSD_6_2_BASE
# 1.36 30-Aug-2016 jmc

use a mixture of .Dl and .Bd -compact to reduce the amount of
vertical whitespace, making it easier to see which hostname.if file
relates to which example;


# 1.35 29-Aug-2016 mpi

Make examples fit in 80 columns, reminded by jmc@


# 1.34 25-Aug-2016 sthen

Fix pfsync(4)'s carp examples: as of ip_carp.c r1.245, carpdev must be
specified. From Bryan Stenson.


Revision tags: OPENBSD_5_8_BASE OPENBSD_5_9_BASE OPENBSD_6_0_BASE
# 1.33 25-Jun-2015 jmc

pfsync and ipsec do not currently work; from lukasz czarniecki
i've chosen to comment out the pertinent text rather than remove it...

confirmation/ok dlg


Revision tags: OPENBSD_5_7_BASE
# 1.32 01-Feb-2015 jsg

Fix a typo in the Nd line. From Steven McDonald.


Revision tags: OPENBSD_4_8_BASE OPENBSD_4_9_BASE OPENBSD_5_0_BASE OPENBSD_5_1_BASE OPENBSD_5_2_BASE OPENBSD_5_3_BASE OPENBSD_5_4_BASE OPENBSD_5_5_BASE OPENBSD_5_6_BASE
# 1.31 29-Apr-2010 henning

fix multicast address, Sebastian Benoit <benoit-lists at fb12.de>


Revision tags: OPENBSD_4_7_BASE
# 1.30 27-Nov-2009 jmc

benefical -> beneficial; from Brad Tilley


Revision tags: OPENBSD_4_6_BASE
# 1.29 17-Jun-2009 sthen

Document the 'defer' ifconfig flag. From me with a few tweaks by dlg@.
reads ok to jmc@.


Revision tags: OPENBSD_4_5_BASE
# 1.28 17-Feb-2009 dlg

massage a bit. note that pfsync in openbsd 4.4 and 4.5 are incompatible.

requested by deraadt@ tweaks by jmc@


Revision tags: OPENBSD_4_4_BASE
# 1.27 03-Jun-2008 jmc

fix some spacing issues;


Revision tags: OPENBSD_4_3_BASE
# 1.26 20-Sep-2007 mpf

Since keep state is the default now, change pf.conf
example to use (no-sync) for pfsync and carp traffic.
OK mcbride@


Revision tags: OPENBSD_4_2_BASE
# 1.25 31-May-2007 jmc

convert to new .Dd format;


Revision tags: OPENBSD_4_1_BASE
# 1.24 23-Oct-2006 jmc

no need to use "keep state" and "flags S/SA" in pf rules,
now that it is the default;

ok henning mcbride camield (ftp-proxy bits) deraadt


Revision tags: OPENBSD_3_8_BASE OPENBSD_3_9_BASE OPENBSD_4_0_BASE
# 1.23 09-Aug-2005 jmc

add Xr to ifstated(8);
ok mpf@


Revision tags: OPENBSD_3_7_BASE
# 1.22 24-Feb-2005 jmc

add carp(4) to SEE ALSO;
from freebsd -r1.4;


# 1.21 06-Feb-2005 mcbride

missing words


# 1.20 20-Jan-2005 mcbride

Document syncif->syncdev change. Also fix order of syncdev option
in ifconfig manpage.


Revision tags: OPENBSD_3_6_BASE
# 1.19 03-Aug-2004 jmc

tweaks;


# 1.18 03-Aug-2004 mcbride

Document 'syncpeer'.


# 1.17 31-Mar-2004 jmc

a little cleanup;


Revision tags: OPENBSD_3_5_BASE
# 1.16 22-Mar-2004 jmc

some spacing, and a little cleanup;
ok deraadt@


# 1.15 22-Mar-2004 mcbride

Add a complete pfsync+carp firewall failover example.

ok deraadt@


# 1.14 21-Mar-2004 miod

Homogeneize config lines for pseudo-devices, and do not put fixed values.


# 1.13 13-Mar-2004 jmc

typos from Lawrence Teo;


# 1.12 24-Dec-2003 mcbride

Update protocol number and multicast group to match reality.

Pointed out by Jorge Severino (jorge at netsecure dot cl)


# 1.11 16-Dec-2003 jmc

pfsync.4:
- new sentence, new line
- kill whitespace at EOL
- escape a dot at EOL

pflog.4:
- subject verb agreement


# 1.10 16-Dec-2003 mcbride

Reorg and better english. Split network synchronisation specifics
into it's own section.


# 1.9 16-Dec-2003 mcbride

1st pass at documenting the new pfsync network synchronisation
functionality.

ok deraadt@


# 1.8 08-Nov-2003 jmc

- ommited -> omitted
- kill some whitespace at EOL
- remove unnecessary args to .Nm


# 1.7 08-Nov-2003 mcbride

Add 'no-sync' state option to prevent state transition messages for states
created by this rule from appearing on the pfsync(4) interface. e.g.

pass in proto tcp to self flags S/SA keep state (no-sync)

ok cedric@ henning@ dhartmei@


Revision tags: OPENBSD_3_4_BASE
# 1.6 06-Jun-2003 jmc

- section reorder
- some macro fixes
- kill whitespace at EOL


# 1.5 01-Apr-2003 mickey

there could be only one


# 1.4 31-Mar-2003 mpech

pfsync interface may need an argument in kernel config like pflog(4).

henning@ ok


Revision tags: OPENBSD_3_3_BASE
# 1.3 30-Nov-2002 mickey

dead e


# 1.2 29-Nov-2002 henning

wording


# 1.1 29-Nov-2002 mickey

das ist pfsync.4