Does ipfw support interface groups?

Julian Elischer julian at elischer.org
Thu May 21 18:12:40 UTC 2009


Freddie Cash wrote:

> Skipto is very powerful, and we use it in some cases.  But I try not
> to use it very often, as it can lead to spaghetti rules that are hard
> to follow.  :)  We have one firewall where it takes a good 10 minutes
> to track the path a packet takes through the rulelist, as there are so
> many skipto rules and multiple interfaces/vlans (it's scheduled for a
> rewrite this summer).

don't forget you can now do a skipto tablearg  :-)





More information about the freebsd-ipfw mailing list