[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Skipping interfaces in pf [was: pf filtering on loopback?]



On Tue, Dec 14, 2004 at 02:39:25PM -0500, Mike Frantzen wrote:

> That thread is long and I'm lazy, but why not just prefix your ruleset
> with:

There are cases where the state check has unwanted side-effects that you
can't prevent with any existing construct, like the example given for
loopback (I'm to lazy to write an executive summary here ;). This is
mainly relevant for virtual interfaces and features like
route/reply/dup-to or synproxy, it doesn't warrant a large or complex
additional feature. But the proposal is neither, IMO.

I'm not using the argument regarding performance at all, I doubt it will
make a significant difference in most setups. But it won't make anything
slower, in any case (the flag check is as cheap as it gets).

Daniel



Visit your host, monkey.org