Lines Matching +full:permanently +full:- +full:attached
35 .Bk -words
104 Set them permanently in
111 .Bl -tag -width Ds
150 .Bd -literal -offset indent
151 # pfctl -a "authpf/smith(1234)" -s rules
158 .Bd -literal -offset indent
159 # pfctl -a foo/bar -t mytable -T add 1.2.3.4 5.6.7.8
180 .Bd -literal -offset indent
181 # pfctl -a 'authpf/*' -sr
187 .Bd -literal -offset indent
188 # pfctl -a '*' -sr
208 .Bl -tag -width xxxxxxxxxxxx -compact
273 .Dl # pfctl -k host
286 .Dl # pfctl -k host1 -k host2
290 .Dl # pfctl -k 192.168.1.0/24 -k 172.16.0.0/16
296 .Dl # pfctl -k 0.0.0.0/0 -k host2
307 .Dl # pfctl -k label -k foobar
310 (as shown by pfctl -s state -vv),
316 .Dl # pfctl -k id -k 4823e84500000003
321 .Dl # pfctl -k id -k 4823e84500000018/2
323 It is also possible to kill states created from a rule with the route-to/reply-to
325 Note that rules routing via the default routing table (not via a route-to
329 .Dl # pfctl -k gateway -k 192.168.0.1
334 .Dl # pfctl -k gateway -k 192.168.0.0/24
336 States can also be killed based on their pre-NAT address:
338 .Dl # pfctl -k nat -k 192.168.0.1
343 This applies to states killed using the -k option and also will apply to the
348 .Dl # pfctl -M -i interface -Fs
354 .Bd -literal -offset indent
355 # echo "set loginterface fxp0" | pfctl -mf -
368 .Bl -tag -width xxxxxxxxxxxx -compact
399 .Bl -tag -width xxxxxxxxxxxxx -compact
406 per-queue statistics are also shown.
416 the per-rule statistics (number of evaluations,
422 the per-rule statistics (number of evaluations,
432 Show the currently loaded anchors directly attached to the main ruleset.
440 is specified, all anchors attached under the target anchor will be
452 Show the running status and provide a non-zero exit status when disabled.
454 Show per-rule statistics (label, evaluations, packets total, bytes total,
485 .Bl -tag -width xxxxxxxxxxxx -compact
512 Clear statistics only for addresses with non-zero statistics. Addresses
522 .Bd -literal -offset indent
523 # pfctl -Tl -f pf.conf
550 .Bl -tag -width XXX -compact
583 .Bd -literal -offset indent
585 pass out to <test>\en" | pfctl -f-
586 # ping -qc10 ftp.openbsd.org
596 .Bd -literal -offset indent
597 # pfctl -t test -vTshow
616 .Bd -literal -offset indent
617 # pfctl -vvsTables
618 --a-r-C test
631 As we can see here, only one packet \- the initial ping request \- matched the
652 .Bl -tag -width XXX -compact
677 tables of the same name from anchors attached below it.
679 This flag is set when per-address counters are enabled on the table.
694 .Bl -tag -width xxxxxxxxxxxx -compact
705 Clear per-rule statistics.
708 .Bl -tag -width "/etc/pf.conf" -compact
722 .Xr ftp-proxy 8 ,