tech-net archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: NPF: fast kick



Maxime Villard <max%m00nbsd.net@localhost> wrote:
> The change I made was exactly your first sentence: perform minimum sanity
> checks, to ensure the basic operation of NPF. If the basic operation
> cannot be assured, then fast-kick the packet.
> 
> If you pass the packet to the ruleset machinery, things can go wrong,
> because the basic operation of the machinery cannot be assured.

And why not?

-- 
Mindaugas


Home | Main Index | Thread Index | Old Index