> I still think we should split the current "one huge list of rules"
> into several lists:

>       Two lists per interface:
>               one list of rules for inbound packets
>               one list of rules for outbound packets
> 
>       Two lists for the IP stack:
>               one list of rules for incoming packets
>               one list of rules for outgoing packets
> 
>       One list for forwarding of packets.

aren't these three classes combined in some H-shaped way ?

        cheers
        luigi

-----------------------------------+-------------------------------------
  Luigi RIZZO, [EMAIL PROTECTED]  . Dip. di Ing. dell'Informazione
  http://www.iet.unipi.it/~luigi/  . Universita` di Pisa
  TEL/FAX: +39-050-568.533/522     . via Diotisalvi 2, 56126 PISA (Italy)
  Mobile   +39-347-0373137
-----------------------------------+-------------------------------------


To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-current" in the body of the message

Reply via email to