[RFC][patch] Two new actions: state-allow and state-deny

Jason Lewis me at sharktooth.org
Wed Feb 4 15:13:01 UTC 2015


The possible issue is is that once NAT changes the IP address and
possibly the port number, state tracking can no longer be applied.
AKA, the packet headers before the NAT is different than the packet
headers after.  This is why NAT needs to track the state instead of
ipfw.


More information about the freebsd-ipfw mailing list