Then you have a default pass rule set. So PF is not the source of the problem. I'm not out of guesses, though. My second guess: Are you running a DNS server on your host? If not, then you've misconfigured your guest's domain name server address.
---
Local interfaces can simplify running vmm(4) guests. Once they became available I switched to using them exclusively for all of my guests. With a local interface, there is no need for a bridge(4), no need for any vether(4) device, and no need for static networking on guests. See my comments in my first post above regarding where to learn about this feature.
|