nat vs. state

Earl A. Killian earl at killian.com
Thu Apr 10 06:52:27 PDT 2003


Is it safe to assume packets diverted to NAT are "safe" and don't need
further checking?  In particular, can the use of dynamic/stateful
rules be skipped for NAT packets?  It seems so, because NAT is already
stateful.


More information about the freebsd-ipfw mailing list