From owner-freebsd-net@FreeBSD.ORG Sun Apr 15 21:53:36 2007 Return-Path: X-Original-To: freebsd-net@freebsd.org Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id F399416A400 for ; Sun, 15 Apr 2007 21:53:35 +0000 (UTC) (envelope-from freebsd-net@m.gmane.org) Received: from ciao.gmane.org (main.gmane.org [80.91.229.2]) by mx1.freebsd.org (Postfix) with ESMTP id AD73F13C4B8 for ; Sun, 15 Apr 2007 21:53:35 +0000 (UTC) (envelope-from freebsd-net@m.gmane.org) Received: from list by ciao.gmane.org with local (Exim 4.43) id 1HdCf1-000455-UV for freebsd-net@freebsd.org; Sun, 15 Apr 2007 23:53:27 +0200 Received: from 83-131-166-8.adsl.net.t-com.hr ([83.131.166.8]) by main.gmane.org with esmtp (Gmexim 0.1 (Debian)) id 1AlnuQ-0007hv-00 for ; Sun, 15 Apr 2007 23:53:27 +0200 Received: from ivoras by 83-131-166-8.adsl.net.t-com.hr with local (Gmexim 0.1 (Debian)) id 1AlnuQ-0007hv-00 for ; Sun, 15 Apr 2007 23:53:27 +0200 X-Injected-Via-Gmane: http://gmane.org/ To: freebsd-net@freebsd.org From: Ivan Voras Date: Sun, 15 Apr 2007 23:53:15 +0200 Lines: 31 Message-ID: References: <20070415144922.A39338@xorpc.icir.org> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="------------enig7B0B050950F35736A5A4709C" X-Complaints-To: usenet@sea.gmane.org X-Gmane-NNTP-Posting-Host: 83-131-166-8.adsl.net.t-com.hr User-Agent: Thunderbird 1.5.0.10 (Windows/20070221) In-Reply-To: <20070415144922.A39338@xorpc.icir.org> X-Enigmail-Version: 0.94.3.0 Sender: news Subject: Re: ipfw, keep-state and limit X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 15 Apr 2007 21:53:36 -0000 This is an OpenPGP/MIME signed message (RFC 2440 and 3156) --------------enig7B0B050950F35736A5A4709C Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Luigi Rizzo wrote: > if i remember well (the implementation dates back to 2001 or so) > you just need to use "limit", as it implicitly installs > a dynamic state entry (same as keep-state). Thanks, I'll try it tomorrow. If it works, may I suggest a change: make the error message say "keep-state is redundant with limits" and proceed like only "limits" exists? --------------enig7B0B050950F35736A5A4709C Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFGIp7LldnAQVacBcgRArqtAJ9kfZ/QrGFhQ9prwmEeY8pikFsLMwCg1D+U 2aQjCaCtj+vV/c1jcDPcIFw= =O4d4 -----END PGP SIGNATURE----- --------------enig7B0B050950F35736A5A4709C--