From owner-freebsd-ipfw@FreeBSD.ORG Wed Apr 30 00:14:28 2003 Return-Path: Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 283D237B401 for ; Wed, 30 Apr 2003 00:14:28 -0700 (PDT) Received: from mx1.lphp.org (APastourelles-107-1-5-101.abo.wanadoo.fr [193.252.221.101]) by mx1.FreeBSD.org (Postfix) with ESMTP id E83C843FBF for ; Wed, 30 Apr 2003 00:14:26 -0700 (PDT) (envelope-from ajacoutot@lphp.org) Received: from sta01 (sta01.lphp.org.local [192.168.0.4]) by mx1.lphp.org (8.12.8p1/8.12.8) with ESMTP id h3U7EIRs070050; Wed, 30 Apr 2003 09:14:18 +0200 (CEST) (envelope-from ajacoutot@lphp.org) From: Antoine Jacoutot To: cjclark@alum.mit.edu, "Crist J. Clark" Date: Wed, 30 Apr 2003 09:14:18 +0200 User-Agent: KMail/1.5.1 References: <200304271259.02025.ajacoutot@lphp.org> <200304300100.42983.ajacoutot@lphp.org> <20030430045856.GA23926@blossom.cjclark.org> In-Reply-To: <20030430045856.GA23926@blossom.cjclark.org> MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit Content-Disposition: inline Message-Id: <200304300914.18382.ajacoutot@lphp.org> cc: freebsd-ipfw@freebsd.org Subject: Re: ipfw dynamic rule timeout X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 30 Apr 2003 07:14:28 -0000 On Wednesday 30 April 2003 06:58, Crist J. Clark wrote: > I think several of the articles point to the easiest solution: Don't > use keep-state rules in conjunction with natd(8). Keep-state doesn't > offer you anything more than using natd(8) with stateless rules for > the vast majority of policies. Yes, thanks, that's what I though too. I guess I'll just have to write a new "stateless" ruleset (I always used keep-state). Regards. Antoine