On 1/21/25 05:57, Pete Long wrote:
Finally how can I segregate two different networks using NPF? Here's what I have right now and there are no VLANs involved. group "internal" on $int_if { block stateful in from $wifinet pass in all pass out all }
Probably your 'block stateful in from $wifinet' is overridden by the subsequent 'pass in all'
NPF.CONF(5) says:
If a packet matches a rule which has the final option set, this rule is considered the last matching rule, and evaluation of subsequent rules is skipped. Otherwise, the last matching rule is used.