If I create a rule:
pass out quick on $iface proto tcp from any to any flags S/SA modulate state
the connections don't initiate. Replacing 'flags S/SA modulate state' to
'keep state' salvages this.
#2 Updated by bastyaelvtars over 8 years ago
Behind my other bridge, the aforementioned page loads. I recall reports
on similar behaviour with OpenBSD 3.6, we did not have this with OpenBSD
3.7 and 3.8. I think the only salwage for this will be a PF update in
the base system, until then, I'll redirect the requests targeting this
(popular) website to an HTTP proxy.
#3 Updated by bastyaelvtars about 8 years ago
The non-loadinbg web page issue seems to be fixed by Matt's commit:
However, the 'modulate state' thing still does not work.