IPFW - Keep State

Mel fbsd.questions at rachie.is-a-geek.net
Fri Aug 31 07:04:24 PDT 2007


On Friday 31 August 2007 15:38:57 Grant Peel wrote:

> I don't use NAT, so  is there any other compelling reasons? Speed etc?

Speed is one. The dynamic rules only evaluate protocol, IP addresses and 
ports. Whether this is noticeable, only you can tell.

Also, if you're passing through traffic through other means (routing, 
bridging), that expects replies via the reverse route. So basically 
everything except local servers come to think of it.

You may wanna look into: `sysctl net.inet.ip.fw | grep dyn_'.
-- 
Mel


More information about the freebsd-questions mailing list