Actions
Feature #16215
closedAllow floating rules using the "match" action to match based on IP Options
Start date:
Due date:
% Done:
100%
Estimated time:
Plus Target Version:
25.11
Release Notes:
Default
Description
Match rules now support matching traffic with "allow-opts":
https://cgit.freebsd.org/src/commit/?id=7e70d94acd68b3ac6b45f49d4ab7a0f7867c3ea7
Note that this is a "sticky" option meaning that "pass" rules inherit the "allow-opts" option from the "match" rule.
Related issues
Updated by Marcos M 10 months ago
- Related to Feature #16068: Option to disable logging of packets blocked due to unmatched IP options added
Updated by Georgiy Tyutyunnik 10 months ago
patch allows "match" rule creation with IP options enabled. resulting floating rule logs igmp traffic
tested on
25.07-DEVELOPMENT (amd64)
built on Thu May 29 19:08:00 UTC 2025
FreeBSD 15.0-CURRENT
Updated by Georgiy Tyutyunnik 9 months ago
- Status changed from Feedback to Resolved
Updated by Jim Pingle 8 months ago
- Plus Target Version changed from 25.07 to 25.11
Updated by Jim Pingle 4 months ago
- Subject changed from Allow matching on IP Options with firewall match rules to Allow floating rules using the "match" action to match based on IP Options
Actions