PF firewall rules

Greg Hennessy Greg.Hennessy at nviz.net
Tue Jul 11 10:39:36 UTC 2006


 
> >
> >   
> is it safe to say to just remove the "keep state" behavior 
> for udp and other connectionless packets? 

No. Anything but. 

If you don't keep state, you would have to specifically code wide open
ingress packet filtering rules for reply traffic. 


Greg







More information about the freebsd-pf mailing list