Allowing PF to skip interfaces

Contributed by grey on from the catching up on CVS changes dept.

Thanks to kris and several others writing in to let us know about this pf improvement from last week:

Introduce 'set skip on <ifspec>' to support a list of interfaces where no packet filtering should occur (like loopback, for instance). Code from Max Laier, with minor improvements based on feedback from deraadt@. ok mcbride@, henning@

The full commit message may be found here.

  1. By Anonymous Coward ( on

    this is nice. now i can have a public filtered and public unfiltered networks right through pf

  2. By Anonymous Coward ( on

    So this does pretty much the same as "pass quick on <ifname>", but only a little bit faster? Or am I missing something obvious here?

    1. By hackmann ( on

      Yes, pretty much

    2. By djm@ ( on

      It skips checking the state tree


