On Monday 07 April 2008 17:05:32 Matthew Dillon wrote:You will want this change, too: http://www.freebsd.org/cgi/cvsweb.cgi/src/sys/contrib/pf/net/pf.c#rev1.51 if you turn on "flags S/SA" by default. Note that processing the ruleset is *really* expensive. Keep state whereever, whenever you can. I agree that the tcp checking is a bit overzealous, but not keeping state at all is not a good idea. I don't know what the most reasonable default is, but offering a way to switch off the extended tcp checking is certainly a good thing. I think I will take this to FreeBSD sooner or later, but will keep conservative defaults. i.e. "flags S/SA keep state (nopickups)" in your current proposed naming. -- /"\ Best regards, | mlaier@freebsd.org \ / Max Laier | ICQ #67774661 X http://pf4freebsd.love2party.net/ | mlaier@EFnet / \ ASCII Ribbon Campaign | Against HTML Mail and News
| debian developer | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Greg Kroah-Hartman | [PATCH 002/196] Chinese: rephrase English introduction in HOWTO |
| Linus Torvalds | Re: Long delay in resume from RAM (Was Re: [patch 00/69] -stablereview) |
| Parag Warudkar | BUG: soft lockup - CPU#1 stuck for 15s! [swapper:0] |
git: | |
| Andi Kleen | [PATCH RFC] [4/9] modpost: Fix format string warnings |
| Rick Jones | Re: Network latency regressions from 2.6.22 to 2.6.29 |
| Antonio Almeida | HTB accuracy for high speed |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
