Unix Technical Forum

RFD: possibility to set timeouts on a per rule basis in PF

This is a discussion on RFD: possibility to set timeouts on a per rule basis in PF within the mailing.openbsd.tech forums, part of the OpenBSD category; --> Hello, I think it would be very nice to have a feature to set timeouts on per rule basis. ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > mailing.openbsd.tech

Register FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-18-2008, 09:25 AM
Gregory Edigarov
 
Posts: n/a
Default RFD: possibility to set timeouts on a per rule basis in PF

Hello,

I think it would be very nice to have a feature to set timeouts on per
rule basis.
There should be an option 'timeout' which may be placed in some rules
that are keeping state. nat and rdr are the first example.
Now timeouts are set globally, which causes some unnecessary overhead
and I believe make state tables a bit overcrowded in case
timeouts for some type of packets or timeouts for some service should be
high.

What do others think?
I've just had to 'set timeout other.{first,single,multiple}' to 86400
as i have to rdr gre protocol to frickin (pptp proxy), but i think it is
too global setting.

--
With best regards,
Gregory Edigarov

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 01:39 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com