Re: CARP and OUT rules
Joey Morin <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.m0n0wall |
|---|---|
| Message-ID | <CADJ4=eon=qPer5W3yv4Cn1DRrUe3OA=CLgDmWP_YEhyuP2h2Mw@mail.gmail.com> |
On Wed, Sep 7, 2011 at 5:41 PM, Tonix (Antonio Nati) <[email protected]>wrote: > Il 07/09/2011 22:32, Joey Morin ha scritto: > > On Wed, Sep 7, 2011 at 11:53 AM, Tonix (Antonio Nati) >> <[email protected]>wrote: >> >> With this small change manageability would become fantastic for ISP >>> environments. >>> Rules would be much less, and general speed of monowall would be better. >>> >>> while i agree that this kind of feature would be much easier to manage >> and >> maintain (especially in a situation with soooo many interfaces), it's >> unlikely that it would improve performance. i suspect that the >> configuration feature you seek would still need to generate individual >> rules >> for each interface, either at configuration time or dynamically at run >> time. >> >> > Why? > i assumed that ipfilter would manage queues for each interface, rather than one big queue for the whole box.