Structured PF rules, validated with pfctl -nf before any apply.
An existing /etc/pf.conf ruleset is present that OgmaProtect
does not yet manage. Until you import it, the firewall shown here is empty
and drift alarms may fire. Importing brings your existing rules under
OgmaProtect management (your current /etc/pf.conf is saved to
/var/db/ogmaprotect/config/pf.conf.preadopt first) and applies them with
the usual auto-revert window so you can review and Keep or Revert.
A ruleset that uses anchors, includes or !
commands cannot be imported automatically — you will get a message to
migrate it by hand (see the INSTALL guide).
A live PF change by {{PENDING_ACTOR}} is awaiting confirmation and reverts automatically in {{PENDING_REMAINING}} seconds unless you keep it.
If this page stops loading after an apply, do nothing — the firewall reverts by itself at the deadline.
{{#PENDING_REVERT_FAILED}}ogmaprotectctl pf cancel {{PENDING_TXN_ID}}
Enabling PF live arms a confirmation window: unless you confirm over this page within the window, the change reverts automatically — no console needed. Rules that block management access can still lock out this session until the revert fires.
{{/WRITE}}This firewall was configured with raw pf.conf text, which the visual editor cannot represent. The current rules are shown read-only in the Preview tab below. The raw editor has been removed — to manage this firewall here, convert it to the visual editor. Converting discards the raw rules; the live firewall keeps running unchanged until you build and apply a new ruleset.
Live state table requires JavaScript.
| NAT | Dir | Expiry | Actions |
|---|
| Source | Dest | States | Connections | Rate |
|---|
Live entries of this PF table (pfctl -t <name> -T show -v). Removing an entry unblocks that address. Counters appear only for counters tables.
| Address | Cleared | Packets (in/out) | Bytes (in/out) | Actions |
|---|
| Time | Action | Iface | Rule | Packet |
|---|
Decoded from the binary /var/log/pflog via tcpdump -r. Enter a rule number to watch hits for one rule. This shows only packets matched by rules that carry the log keyword, and may be empty on a stock configuration. Requires pf:*:read + log:*:read.