Firewall Wizards mailing list archives
Rationale for BSD (I)PF rule order?
From: "Volker Tanger" <volker.tanger () discon de>
Date: Thu, 8 May 2003 14:59:39 +0200
Greetings! I was not able to find a rationale for the BSD type of packet filter application. Where most FW/ACL implementations follow "first match", BSD usually takes "last match" (if you don't use the "quick" method). Is there a reason why that was decided this way? Especially as I currently cannot see advantages for this behaviour, only performance disadvantages. Can someone enlighten me here? Thanks a lot Volker Tanger IT-Security discon gmbh DeTeWe AG & Co. KG Fon +49 30 6104-3307 Fax +49 30 6104-3435 http://www.detewe.de/ -- ------------------------------------------------------------------- Besuchen Sie unsere neuen Internet-Seiten http://www.detewe.de . Neues Highlight: Wunschproduktberater fuer den Home & Office-Bereich. Visit our new Internet Pages on http://www.detewe.de . Our Highlight: Online Product Adviser for Home & Office. (Currently available in German only) _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Rationale for BSD (I)PF rule order? Volker Tanger (May 08)
- Re: Rationale for BSD (I)PF rule order? Barney Wolff (May 08)
- Re: Rationale for BSD (I)PF rule order? Henning Brauer (May 09)
- Re: Rationale for BSD (I)PF rule order? Holger Kipp (May 09)
- Re: Rationale for BSD (I)PF rule order? Mikael Olsson (May 09)
- Re: Rationale for BSD (I)PF rule order? Bill Royds (May 09)
- Re: Rationale for BSD (I)PF rule order? Barney Wolff (May 10)
- Re: Rationale for BSD (I)PF rule order? David Pick (May 10)
- Re: Rationale for BSD (I)PF rule order? Mikael Olsson (May 09)
- Re: Rationale for BSD (I)PF rule order? Barney Wolff (May 08)
- <Possible follow-ups>
- RE: Rationale for BSD (I)PF rule order? Smith Gary-GSMITH1 (May 09)
- RE: Rationale for BSD (I)PF rule order? Stewart, John (May 09)
- Re: Rule lookup strategies (Was: Rationale for BSD (I)PF rule order?) Mikael Olsson (May 09)