From owner-freebsd-security Tue Nov 27 4:22:40 2001 Delivered-To: freebsd-security@freebsd.org Received: from guard.ing.nl (guard.ing.nl [194.178.239.66]) by hub.freebsd.org (Postfix) with ESMTP id F1DC037B42A; Tue, 27 Nov 2001 04:22:24 -0800 (PST) Received: by ING-mailhub; id NAA02904; Tue, 27 Nov 2001 13:24:31 +0100 (MET) Received: from somewhere by smtpxd Content-Class: urn:content-classes:message MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Subject: RE: IPFW, natd and an internal FTP server. X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4522.1200 Date: Tue, 27 Nov 2001 13:22:09 +0100 Message-ID: <98829DC07ECECD47893074C4D525EFC321EA16@citsnl007b.europe.intranet> X-MS-Has-Attach: X-MS-TNEF-Correlator: Thread-Topic: IPFW, natd and an internal FTP server. thread-index: AcF3MflKsJcB1A0/TgOK1t2bXQgO7gAC9pgg From: "Carroll, D. (Danny)" Importance: normal To: "Ruslan Ermilov" Cc: X-OriginalArrivalTime: 27 Nov 2001 12:22:10.0757 (UTC) FILETIME=[23558750:01C1773E] Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org :From: Ruslan Ermilov [mailto:ru@FreeBSD.ORG] :On Mon, Nov 26, 2001 at 06:52:23PM +0000, Danny Carroll wrote: :>=20 :Committed to 5.0-CURRENT, will MFC in 1 week. Thanks! : Cooley... Is there a rule of thumb as to how many rules you should allow for punch_fw I mean if I had 100 ftp sessions would a ruleset of 300 be enough? =20 I imagine it would start to slow down rather quickly as teh ipfw rules get larger. -D -----------------------------------------------------------------=0A= ATTENTION:=0A= The information in this electronic mail message is private and=0A= confidential, and only intended for the addressee. Should you=0A= receive this message by mistake, you are hereby notified that=0A= any disclosure, reproduction, distribution or use of this=0A= message is strictly prohibited. Please inform the sender by=0A= reply transmission and delete the message without copying or=0A= opening it.=0A= =0A= Messages and attachments are scanned for all viruses known.=0A= If this message contains password-protected attachments, the=0A= files have NOT been scanned for viruses by the ING mail domain.=0A= Always scan attachments before opening them.=0A= ----------------------------------------------------------------- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message