Ipfw Impossibility - Perpetual Motion Achieved!

Jason C. Wells jcw at highperformance.net
Sun Nov 7 09:18:06 PST 2004


Pray tell how is this report from 'ipfw show' even possible?

17100   3   228 count ip from any to any
65535  27  1986 deny ip from any to any

If rule 17100 only counted three packets, then how did the very next rule 
count 27?  I do not use 'skipto' rules.

We appear to be passing more packets out of rule 17100 than are going in. 
If we can harness this energy, we can power the universe! :)

Thanks,
Jason C. Wells


More information about the freebsd-questions mailing list