From owner-freebsd-ipfw@FreeBSD.ORG Thu May 21 18:12:40 2009 Return-Path: Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 20CAC1065674 for ; Thu, 21 May 2009 18:12:40 +0000 (UTC) (envelope-from julian@elischer.org) Received: from outF.internet-mail-service.net (outf.internet-mail-service.net [216.240.47.229]) by mx1.freebsd.org (Postfix) with ESMTP id 062CD8FC29 for ; Thu, 21 May 2009 18:12:39 +0000 (UTC) (envelope-from julian@elischer.org) Received: from idiom.com (mx0.idiom.com [216.240.32.160]) by out.internet-mail-service.net (Postfix) with ESMTP id 2F2D314DCFD; Thu, 21 May 2009 11:12:40 -0700 (PDT) X-Client-Authorized: MaGic Cook1e X-Client-Authorized: MaGic Cook1e Received: from julian-mac.elischer.org (home.elischer.org [216.240.48.38]) by idiom.com (Postfix) with ESMTP id 3A3E42D6012; Thu, 21 May 2009 11:12:39 -0700 (PDT) Message-ID: <4A159997.9080604@elischer.org> Date: Thu, 21 May 2009 11:12:39 -0700 From: Julian Elischer User-Agent: Thunderbird 2.0.0.21 (Macintosh/20090302) MIME-Version: 1.0 To: Freddie Cash References: <9a542da30905210720y50fafe59ld3459c9e76ef5824@mail.gmail.com> <20090521150113.GA47160@onelab2.iet.unipi.it> <20090521164225.GB50606@onelab2.iet.unipi.it> In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Cc: freebsd-ipfw@freebsd.org Subject: Re: Does ipfw support interface groups? X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 21 May 2009 18:12:40 -0000 Freddie Cash wrote: > Skipto is very powerful, and we use it in some cases. But I try not > to use it very often, as it can lead to spaghetti rules that are hard > to follow. :) We have one firewall where it takes a good 10 minutes > to track the path a packet takes through the rulelist, as there are so > many skipto rules and multiple interfaces/vlans (it's scheduled for a > rewrite this summer). don't forget you can now do a skipto tablearg :-)