Re: IPFilter 5.0.5 - some new knobs...

"Jeremy C. Reed" <[email protected]>
Newsgroups gmane.comp.security.firewalls.ipfilter
Message-ID <13292_1231175136_49623DE0_13292_7030_1_Pine.NEB.4.64.0901051103060.7921@tx.reedmedia.net>
> Rules can be given an expirey (in seconds):
> 
> block in from any to any port = 22 rule-ttl 10
> 
> But displaying them with ipfstat is slightly different, e.g:
> # ipfstat -i
> block in from any to any port = 22 # rule-ttl 4191
> 
> This prevents temporary rules from being loaded that match
> already existing rules and also means you don't need to
> worry about guessing the correct ttl to remove a rule.

Any more examples of this? It seems confusing to use the same "rule-ttl" 
for different purposes. And also how can you know how much time is left?

Thanks for these interesting and useful features.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.