From owner-freebsd-net@FreeBSD.ORG Thu Apr 25 22:52:53 2013 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.FreeBSD.org [8.8.178.115]) by hub.freebsd.org (Postfix) with ESMTP id C6088D1E for ; Thu, 25 Apr 2013 22:52:53 +0000 (UTC) (envelope-from weiler@soe.ucsc.edu) Received: from mail-pd0-f171.google.com (mail-pd0-f171.google.com [209.85.192.171]) by mx1.freebsd.org (Postfix) with ESMTP id 9C82C103B for ; Thu, 25 Apr 2013 22:52:53 +0000 (UTC) Received: by mail-pd0-f171.google.com with SMTP id t12so2090555pdi.30 for ; Thu, 25 Apr 2013 15:52:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ucsc.edu; s=ucsc-google; h=x-received:message-id:date:from:user-agent:mime-version:to:cc :subject:references:in-reply-to:content-type :content-transfer-encoding; bh=QTZnSsaVRRp6dtAgVCd8J3SUQ5wGdHImF42B7FyYlm4=; b=WDD/SZUM157AwwiETXEjKYDC2geOnZCtmetjPirxtT4UlMUxeJFQZRQFDfCj+PCecG eS0KfVQDTCaaAx/lXb04WLUVeL8AkmLmmHpwNyUf3m0H0USiJfaXiI0OKXqx5RaEgK4x iTFqaSrT8UfyR9XhtTQ25IP1qIeC+g1NgfuDo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=x-received:message-id:date:from:user-agent:mime-version:to:cc :subject:references:in-reply-to:content-type :content-transfer-encoding:x-gm-message-state; bh=QTZnSsaVRRp6dtAgVCd8J3SUQ5wGdHImF42B7FyYlm4=; b=CiELl+TqVK9mFL6mDwG0boNeuwm8xq31eOPlYD0RypxTXqor6M32V7c1ebUXsUZ41+ 8lf9O6sZzaarcGi6Kyns1OSfp7Wz2vbcajq8I0hFmeehUGvOk93XhcmOeFt+XXup+COE 25+OvnDEG9n9OYCfDvhsLmd5qCE3Pr0yjKEkBOceau9KVwtIjqkIsaiOLPyZEG0kaIC5 PmtFIzDVpRF0t5lLieO11VE8Fn+RnZ6zylrnDj/JwVdKhKUAFkzLXJ5ot6aHmJI/gZQb HWgoaFh7trXDl6gkHpKXNj3+pU8kXMs8BAWrZi8vbn08xhZxN0vf+KYgQwI9//XDOJ+M PG/A== X-Received: by 10.68.226.230 with SMTP id rv6mr17527019pbc.55.1366930366903; Thu, 25 Apr 2013 15:52:46 -0700 (PDT) Received: from [172.30.0.50] (hgfw-01.soe.ucsc.edu. [128.114.61.130]) by mx.google.com with ESMTPSA id ih1sm8900755pbb.44.2013.04.25.15.52.44 for (version=TLSv1 cipher=RC4-SHA bits=128/128); Thu, 25 Apr 2013 15:52:45 -0700 (PDT) Message-ID: <5179B3BB.3070101@soe.ucsc.edu> Date: Thu, 25 Apr 2013 15:52:43 -0700 From: Erich Weiler User-Agent: Mozilla/5.0 (X11; Linux i686; rv:10.0.6esrpre) Gecko/20120717 Thunderbird/10.0.6 MIME-Version: 1.0 To: Kajetan Staszkiewicz Subject: Re: pf performance? References: <5176E5C1.9090601@soe.ucsc.edu> <201304240134.22740.vegeta@tuxpowered.net> <517974DA.5090809@soe.ucsc.edu> <201304260021.11209.vegeta@tuxpowered.net> In-Reply-To: <201304260021.11209.vegeta@tuxpowered.net> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Gm-Message-State: ALoCoQl9GWLvMtIFTd7TsbfVRDG6KFdBkTcABHxeJSVLLfAp1miILAfvY6sxX4egh1PpYg8IECrB Cc: freebsd-net@freebsd.org X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 25 Apr 2013 22:52:53 -0000 > How many pf rules do you have?. And, as I asked in my previous post, do you > create states on both sides of the firewall? One interface has 12 rules and other other interface has one rule. We do create states on both sides.