Re: Runtime control for the IPFIREWALL_FORWARD
- From: "Andrey V. Elsukov" <bu7cher@xxxxxxxxx>
- Date: Sat, 16 Dec 2006 12:40:44 +0300 (MSK)
Andrey V. Elsukov wrote:
This introduces quite a bit of extra code into the path of IP packets.
Yes, it will add a few extra checks like a "if (pfil_forward_enabled) {...}"
Some people are very sensitive about anything that slows down that path.
I can introduce a new kernel option - NO_PFIL_FORWARD, which will remove an
extra code from the CUSTOM kernel.
But the GENERIC kernel will be more universal with a new feature.
--
WBR, Andrey V. Elsukov
_______________________________________________
freebsd-net@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-net
To unsubscribe, send any mail to "freebsd-net-unsubscribe@xxxxxxxxxxx"
- References:
- Runtime control for the IPFIREWALL_FORWARD
- From: Andrey V. Elsukov
- Re: Runtime control for the IPFIREWALL_FORWARD
- From: Julian Elischer
- Runtime control for the IPFIREWALL_FORWARD
- Prev by Date: jail addresses and default bindings
- Next by Date: Re: jail addresses and default bindings
- Previous by thread: Re: Runtime control for the IPFIREWALL_FORWARD
- Next by thread: ipf : Does RPC port auto-adding interface exist?
- Index(es):
Relevant Pages
|
|