Unix Technical Forum

Re: rdr quick

This is a discussion on Re: rdr quick within the mailing.openbsd.tech forums, part of the OpenBSD category; --> Ryan McBride wrote: > On Sun, Oct 08, 2006 at 04:17:45AM +0159, Han Boetes wrote: > > since `pass' ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > mailing.openbsd.tech

Register FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-18-2008, 08:54 AM
Han Boetes
 
Posts: n/a
Default Re: rdr quick

Ryan McBride wrote:
> On Sun, Oct 08, 2006 at 04:17:45AM +0159, Han Boetes wrote:
> > since `pass' is used for something else with the rest of the
> > rules it can be confusing to people who think in mathimatical
> > keyword logic instead of language logic.
> >
> > So that's why I wanted to suggest to use `rdr quick' which is
> > consistent with the rest of pf. No need to remove the `rdr
> > pass' statement because of backward compatibility, but it
> > doesn't have to be in the documentation anymore.

>
> By itself the 'quick' keyword only applies to ruleset
> evaluation, halting it at this rule if there is a match. It does
> NOT specify whether the packet should be passed, dropped,
> logged, altered, or otherwise abused.
>
> The 'pass' keyword IS being used consistently in the ruleset:
> wherever you see it, it means the packet will not be blocked if
> this is the matching rule.
>
> Also: Sometimes confusion arises because translation rules are
> all effectively 'quick' rules, as the first matching rule is
> always selected. I'd personally like to see translation rules
> made last-match like the filter rules, and not abusing the
> 'quick' keyword is a good start.


OK, point taken. Thanks for sharing your views.



# Han

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 01:38 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com