Subject: Re: IPF accounting rule limits
To: Michael Graff <>
From: Andrew Brown <>
List: current-users
Date: 04/27/1999 17:54:56
>I have always thought that the way ipf tracks state by looking at the
>packets is wrong.  It seems like a better way would be to attach a
>little bit of state glue to the socket structure, or the udp/tcp
>control blocks.  State only makes sense on UDP and TCP anyway,

not icmp as well?  echo requests/replies have a certain amount of

|-----< "CODE WARRIOR" >-----|             * "ah!  i see you have the internet (Andrew Brown)                that goes *ping*!"       * "information is power -- share the wealth."