Re: pf default deny compile-time option?

2006-07-16 Thread Travis H.
On 7/15/06, Ryan McBride [EMAIL PROTECTED] wrote: Root can do stupid things which compromise security. Obfuscation or needles complexity in an attempt to protect yourself from the root account will only make your system less secure. If every ruleset needs to put a rule in to default to

Re: controlling ext. inbound traffic on int. interface - few doubts/thoughts

2006-07-16 Thread Travis H.
On 7/14/06, Michal Soltys [EMAIL PROTECTED] wrote: Recently I've been writing rules for small router (2 internal interfaces, 1 external, few services running). I've just set 1 queue for the whole inbound (1 mbit) on internal interface, so it won't get stalled by other traffic from int. net to