From owner-freebsd-ipfw@FreeBSD.ORG Wed Feb 4 05:38:34 2015 Return-Path: Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 7ED06DFF; Wed, 4 Feb 2015 05:38:34 +0000 (UTC) Received: from vps1.elischer.org (vps1.elischer.org [204.109.63.16]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "vps1.elischer.org", Issuer "CA Cert Signing Authority" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4F128B68; Wed, 4 Feb 2015 05:38:34 +0000 (UTC) Received: from Julian-MBP3.local (ppp121-45-238-204.lns20.per1.internode.on.net [121.45.238.204]) (authenticated bits=0) by vps1.elischer.org (8.14.9/8.14.9) with ESMTP id t145cT2b041805 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NO); Tue, 3 Feb 2015 21:38:32 -0800 (PST) (envelope-from julian@freebsd.org) Message-ID: <54D1B050.2040706@freebsd.org> Date: Wed, 04 Feb 2015 13:38:24 +0800 From: Julian Elischer User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:31.0) Gecko/20100101 Thunderbird/31.4.0 MIME-Version: 1.0 To: lev@FreeBSD.org, freebsd-ipfw , freebsd-net Subject: Re: [RFC][patch] New "keep-state-only" option References: <54D0F39B.4070707@FreeBSD.org> <54D1AF04.8050106@freebsd.org> In-Reply-To: <54D1AF04.8050106@freebsd.org> Content-Type: text/plain; charset=windows-1252; format=flowed Content-Transfer-Encoding: 7bit Cc: melifaro@FreeBSD.org X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 04 Feb 2015 05:38:34 -0000 On 2/4/15 1:32 PM, Julian Elischer wrote: > On 2/4/15 12:13 AM, Lev Serebryakov wrote: >> >> And variants with multiple NATs and "nat global" becomes as easy as >> this, too! No stupid "skipto", no "keep-state" at "incoming from local >> network" parts of firewall, nothing! >> >> P.S. I HATE this "all any to any" part! > can we get rid of it? (implied).. or just add "everything" > also I am not sure about "keep-state-only".. > how about 'set-state'? or record-state as I started with.. or record-session.. (state always annoyed me) > >