Firewall Wizards mailing list archives
Re: Rule lookup strategies (Was: Rationale for BSD (I)PF rule order?)
From: Gary Flynn <flynngn () jmu edu>
Date: Sat, 10 May 2003 04:41:14 -0400
Mikael Olsson wrote:
"Stewart, John" wrote:Or, IMHO, even better than first or last fit is "best" fit. This is definitely the most "human" way of understanding firewall rules. You don't have to bother with which order they are in at all:I've never worked with this myself, but I've heard people say"it works for small configs, but can do unexpected/unwanted things for large ones".What'd your thoughts on that be?I'm thinking along the lines of "do foo to 0.0.0.0/0 -> 10.0.0.2/32, port 80-81","do bar to 0.0.0.0/0 -> 10.0.0.2/31, port 80". Which one is more specific? There's one IP and two ports in the first one, and two IPs and one port in the other one. (Or subtitute for various other IP and/or protocol/port combinations for other interesting problems).
Precisely. "Best" is in the eyes of the algorithm and it would seem to add more complexity and uncertainty.. I don't want any type of assumptions on the part of the firewall. I want it fully deterministic and to do exactly what I say and nothing more. It should not make assumptions for me on "what is best". Next we'll have a
little paper clip fellow running around the GUI making suggestions. :) _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Re: Rationale for BSD (I)PF rule order?, (continued)
- Re: Rationale for BSD (I)PF rule order? Barney Wolff (May 08)
- Re: Rationale for BSD (I)PF rule order? Henning Brauer (May 09)
- Re: Rationale for BSD (I)PF rule order? Holger Kipp (May 09)
- Re: Rationale for BSD (I)PF rule order? Mikael Olsson (May 09)
- Re: Rationale for BSD (I)PF rule order? Bill Royds (May 09)
- Re: Rationale for BSD (I)PF rule order? Barney Wolff (May 10)
- Re: Rationale for BSD (I)PF rule order? David Pick (May 10)
- Re: Rationale for BSD (I)PF rule order? Mikael Olsson (May 09)
- Re: Rationale for BSD (I)PF rule order? Barney Wolff (May 08)
- RE: Rationale for BSD (I)PF rule order? Smith Gary-GSMITH1 (May 09)
- RE: Rationale for BSD (I)PF rule order? Stewart, John (May 09)
- Re: Rule lookup strategies (Was: Rationale for BSD (I)PF rule order?) Mikael Olsson (May 09)
- Re: Rule lookup strategies (Was: Rationale for BSD (I)PF rule order?) Gary Flynn (May 10)
- Re: Rationale for BSD (I)PF rule order? Darren Reed (May 10)
- Re: Rationale for BSD (I)PF rule order? Avishai Wool (May 11)
- Re: Rationale for BSD (I)PF rule order? Paul Robertson (May 12)
- Re: Rule lookup strategies (Was: Rationale for BSD (I)PF rule order?) Mikael Olsson (May 09)
- Re: Rationale for BSD (I)PF rule order? Bill Royds (May 11)
- Re: Rationale for BSD (I)PF rule order? Marcus J. Ranum (May 12)
- RE: Rationale for BSD (I)PF rule order? Ben Nagy (May 12)
- RE: Rationale for BSD (I)PF rule order? Paul Robertson (May 12)
- RE: Rationale for BSD (I)PF rule order? Marcus J. Ranum (May 12)
- RE: Rationale for BSD (I)PF rule order? Paul Robertson (May 12)