When to use setup keyword?

Chuck Swiger cswiger at mac.com
Sat Oct 4 10:16:21 PDT 2003


Roderick van Domburg wrote:
> Hello everyone,
> 
> I was pondering if blindly trailing every tcp rule with the 'setup' keyword
> would incur any performance loss or security hazard.

It would incur a security hazard.  Any tool which performs "stealth" scans (ie, 
such as nmap's default scan mode) would go right past your firewall rules.

-- 
-Chuck



More information about the freebsd-ipfw mailing list