ipfw Table Organization

Michael Sierchio kudzu at tenebras.com
Tue Aug 24 22:59:59 UTC 2021


On Tue, Aug 24, 2021 at 3:41 PM Tim Daneliuk <tundra at tundraware.com> wrote:

> On 8/24/21 5:30 PM, Michael Sierchio wrote:
> > Do you really mean 100,000 firewall rules?  100,000 CIDR blocks is not
> > a problem.  You should probably consolidate CIDR blocks before adding
> them
> > to a
> > table, because it's a longest-prefix-match.
>
>
> Most of the 100,000 are CIDR blocks but there are probably on the order
> of 5000-ish IPs
>

An IPv4 address is a CIDR block with a netmask of /32 ;-)


More information about the freebsd-questions mailing list