:You will want this change, too:
:http://www.freebsd.org/cgi/cvsweb.cgi/src/sys/contrib/pf/net/pf.c#rev1.51
:if you turn on "flags S/SA" by default.
Done, thank you! Initial patch set will be posted in follow-up in
just a sec.
:Note that processing the ruleset is *really* expensive. Keep state
:whereever, whenever you can. I agree that the tcp checking is a bit
:overzealous, but not keeping state at all is not a good idea.
:
:I don't know what the most reasonable default is, but offering a way to
:switch off the extended tcp checking is certainly a good thing. I think
:I will take this to FreeBSD sooner or later, but will keep conservative
:defaults. i.e. "flags S/SA keep state (nopickups)" in your current
:proposed naming.
:
:--
:/"\ Best regards, | mlaier@freebsd.org
:\ / Max Laier | ICQ #67774661
Yes, I see the reasoning behind keep state. If keep state were on
by default, though, I think I'd want it to be pickups rather then
no-pickups. I just can't wrap my head around it blowing up TCP
connections. However, if one explicitly specified a keep state
directive for a rule, I agree the default should be no-pickups.
-Matt| Al Viro | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Greg KH | [2.6.22.2 review 05/84] Fix deadlocks in sparc serial console. |
| Linus Torvalds | Linux 2.6.27-rc8 |
| Greg Kroah-Hartman | [PATCH 006/196] Chinese: add translation of oops-tracing.txt |
git: | |
| Natalie Protasevich | [BUG] New Kernel Bugs |
| Jarek Poplawski | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Linus Torvalds | Re: [GIT]: Networking |
| Gerrit Renker | [PATCH 0/37] dccp: Feature negotiation - last call for comments |
| Manuel Bouyer | Re: Interactive performance in -current |
| YAMAMOTO Takashi | Re: statvfs(2) replacement for statfs(2) patch |
| Nathan Langford | microkernels |
| Garrett D'Amore | Re: wsmux inject |
