From owner-freebsd-ipfw@FreeBSD.ORG Fri Feb 6 10:13:28 2004 Return-Path: Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id B044516A4CE for ; Fri, 6 Feb 2004 10:13:28 -0800 (PST) Received: from xorpc.icir.org (xorpc.icir.org [192.150.187.68]) by mx1.FreeBSD.org (Postfix) with ESMTP id D13B143D46 for ; Fri, 6 Feb 2004 10:13:26 -0800 (PST) (envelope-from rizzo@icir.org) Received: from xorpc.icir.org (localhost [127.0.0.1]) by xorpc.icir.org (8.12.9p1/8.12.8) with ESMTP id i16IDQAF063380; Fri, 6 Feb 2004 10:13:26 -0800 (PST) (envelope-from rizzo@xorpc.icir.org) Received: (from rizzo@localhost) by xorpc.icir.org (8.12.9p1/8.12.3/Submit) id i16IDQuR063379; Fri, 6 Feb 2004 10:13:26 -0800 (PST) (envelope-from rizzo) Date: Fri, 6 Feb 2004 10:13:26 -0800 From: Luigi Rizzo To: Don Bowman Message-ID: <20040206101326.B62986@xorpc.icir.org> References: Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.2.5.1i In-Reply-To: ; from don@sandvine.com on Fri, Feb 06, 2004 at 01:09:48PM -0500 cc: "'Jack L. Stone'" cc: freebsd-ipfw@freebsd.org Subject: Re: Syntax to block 38 IPs X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 06 Feb 2004 18:13:28 -0000 On Fri, Feb 06, 2004 at 01:09:48PM -0500, Don Bowman wrote: ... > deny ip from { 209.102.202.131, 209.102.202.132, ...} to any this is still inefficient. Better to use deny ip from 209.102.202.0/24{131,132,157,190,1,86} ... which uses a bitmap to represent the list of hosts and has constant processing time as opposed to having to scan a list. cheers luigi > this uses IPFW2 I think. > > from the shell, remember to escape the { as \{. > > you could also send a RST i suppose, but just dropping it is > best. > > _______________________________________________ > freebsd-ipfw@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-ipfw > To unsubscribe, send any mail to "freebsd-ipfw-unsubscribe@freebsd.org"