Re: FairQ ALTQ for PF - Patch #2

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <kernel@...>
Date: Monday, April 7, 2008 - 11:53 am

On Monday 07 April 2008 17:05:32 Matthew Dillon wrote:

You will want this change, too:
http://www.freebsd.org/cgi/cvsweb.cgi/src/sys/contrib/pf/net/pf.c#rev1.51
if you turn on "flags S/SA" by default.


Note that processing the ruleset is *really* expensive.  Keep state 
whereever, whenever you can.  I agree that the tcp checking is a bit 
overzealous, but not keeping state at all is not a good idea.

I don't know what the most reasonable default is, but offering a way to 
switch off the extended tcp checking is certainly a good thing.  I think 
I will take this to FreeBSD sooner or later, but will keep conservative 
defaults.  i.e. "flags S/SA keep state (nopickups)" in your current 
proposed naming.

-- 
/"\  Best regards,                      | mlaier@freebsd.org
\ /  Max Laier                          | ICQ #67774661
 X   http://pf4freebsd.love2party.net/  | mlaier@EFnet
/ \  ASCII Ribbon Campaign              | Against HTML Mail and News
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: FairQ ALTQ for PF - Patch #2, Matthew Dillon, (Mon Apr 7, 11:05 am)
Re: FairQ ALTQ for PF - Patch #2, Simon 'corecode' Schubert..., (Mon Apr 7, 11:51 am)
Re: FairQ ALTQ for PF - Patch #2, Max Laier, (Mon Apr 7, 11:53 am)