the ticket is for a different issue
Please keep discussions on the forum.
don't mind if you open a new ticket for it to put it up for debate
@67 pass log quick inet6 proto carp from any to ff02::12 keep state label "8536b4a11fbacd6adaebd0cf9d91aeeb"@68 pass log quick inet proto carp from any to 224.0.0.18 keep state label "05400a7f8083285e1da2257e85fecd27"
@0 no nat proto carp all@0 no rdr proto carp all
I think you could follow the same argument about other auto generated rules too. For example, why are there all those "IPv6 RFC4890 requirements (ICMP)" if somebody doesn't even use IPv6?I think it's a design choice to prevent common mistakes generating lots of support.I'm not choosing a side here though, just contributing my opinion.(My opinion is I like those rules because they save me time and prevent human error while not impacting security)