Subject: Re: Does ipf filter a packet once or twice?
To: Jukka Marin <jmarin@pyy.jmp.fi>
From: ali \(Anders Lindgren\) <dat94ali@ludat.lth.se>
List: netbsd-users
Date: 04/10/2001 02:12:48
Although I suck at IPF myself and haven't managed to tighten
up my own firewall properly without breaking everything there
is, I recommend the quite easily understood IPF HOWTO you'll
find a link to in the documentation section of http://www.netbsd.org/

It's quite lengthy and makes things seem really simple (at least until
you discover nothing works and you have to keep reading... ;) ).

Among other things, it explains that the "quick" keyword means
to short-circuit the evaluation (i.e. if a matching rule is found
and it has the "quick" keyword, no further comparisons are made; in
this case, your blocking ep1 out rules).

Good luck

-- 
/ali: Computer Science Major and aspiring cartoonist. :-) 
(dept) dat94ali@ludat.lth.se - http://www.ludat.lth.se/~dat94ali
(home) ali@h543.sparta.lu.se - http://h543.sparta.lu.se/
* A4000/040-40/CV3D/Ariadne·AmigaOS·NetBSD·A3000/040-25/Ariadne *