tech-net archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: ipfilter: keep state per-interface?



> FYI: from NetBSD's NPF `man 5 npf.conf'
> | Stateful packet inspection is enabled using `stateful' or
> | `stateful-ends' keywords.  The former creates a state which is
> | uniquely identified by a 5-tuple (source and destination IP
> | addresses, port numbers and an interface identifier).  The latter
> | excludes the interface identifier and must be used with precaution.
Thanks!  I guess I'll use it as an excuse to learn some npf :-)


Home | Main Index | Thread Index | Old Index