[RFC][patch] New "keep-state-only" option

Julian Elischer julian at freebsd.org
Wed Feb 4 05:38:34 UTC 2015


On 2/4/15 1:32 PM, Julian Elischer wrote:
> On 2/4/15 12:13 AM, Lev Serebryakov wrote:
>>
>>   And variants with multiple NATs and "nat global" becomes as easy as
>> this, too! No stupid "skipto", no "keep-state" at "incoming from local
>> network" parts of firewall, nothing!
>>
>> P.S. I HATE this "all any to any" part!
> can we get rid of it?  (implied).. or just add "everything"
> also I am not sure about "keep-state-only"..
> how about 'set-state'?  or record-state as I started with..
or record-session.. (state always annoyed me)

>
>



More information about the freebsd-net mailing list