Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 14 Feb 2005 23:44:32 -0500
From:      chip <chip.gwyn@gmail.com>
To:        Pat Maddox <pergesu@gmail.com>
Cc:        freebsd-questions@freebsd.org
Subject:   Re: Configuring PF
Message-ID:  <64a8ad9805021420444eb3ccd2@mail.gmail.com>
In-Reply-To: <810a540e050214203221952797@mail.gmail.com>
References:  <810a540e050214203221952797@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help
> quickly see what's up.  When PF is disabled, I can nmap it in about 9
> seconds.  When I turn it on, it takes over 3 minutes to do.  These
> machines are on the same network, so the connection is obviously fast.

I believe this is becuase nmap is having to wait on the connections to
time out.  If you tell PF to 'reject' instead of 'drop' it may go a
bit faster.

-- 
Just my $.02, your mileage may vary,  batteries not included, etc....



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?64a8ad9805021420444eb3ccd2>