Re: IPFW + me

From: Peter Ross <Peter.Ross(at)alumni.tu-berlin.de>
Date: Fri, 20 Sep 2002 09:24:36 +0200 (MET DST)

Hi,

Bernd Walter schrieb:

> ${fwcmd} add 10 check-state
> ${fwcmd} add 200 pass tcp from me to any 80 out via ${oif} keep-state

Spricht etwas dagegen, stattdessen

$fwcmd add allow tcp from ${intern_ip} to any 80 setup
$fwcmd add pass tcp from any to any established

zu verwenden? Ich vermute, das wuerde effizienter sein, weil keine
dynamischen Regeln erzeugt werden.

Gruss
Peter

To Unsubscribe: send mail to majordomo(at)de.FreeBSD.org
with "unsubscribe de-bsd-questions" in the body of the message
Received on Fri 20 Sep 2002 - 09:25:10 CEST

search this site