freebsd 8
Peter Maxwell
peter at allicient.co.uk
Fri Jan 8 10:31:24 UTC 2010
2010/1/8 Olivier Thibault <Olivier.Thibault at lmpt.univ-tours.fr>:
>> # keep stats of outging connections
>> pass out keep state
>
> This rule allows everything out and next outgoing rules won't be checked as
> this one first match.
That's incorrect, pf does the opposite and uses the *last* match - at
least that's what the documentation says...
http://www.openbsd.org/faq/pf/filter.html
The quick keyword is used for shortcut evaluation.
More information about the freebsd-pf
mailing list