Subject: Re: IPF accounting rule limits
To: Michael Graff <explorer@flame.org>
From: Andrew Brown <atatat@atatdot.net>
List: current-users
Date: 04/27/1999 17:54:56
>I have always thought that the way ipf tracks state by looking at the
>packets is wrong.  It seems like a better way would be to attach a
>little bit of state glue to the socket structure, or the udp/tcp
>control blocks.  State only makes sense on UDP and TCP anyway,
>presently.

not icmp as well?  echo requests/replies have a certain amount of
state...

-- 
|-----< "CODE WARRIOR" >-----|
codewarrior@daemon.org             * "ah!  i see you have the internet
twofsonet@graffiti.com (Andrew Brown)                that goes *ping*!"
andrew@crossbar.com       * "information is power -- share the wealth."