On Thu, Mar 20, 2003 at 02:16:02PM -0700, [EMAIL PROTECTED] wrote: > Again: traffic can originate on the firewall box. Since this traffic > never passes inbound on an interface, filtering MUST be done > on the outbound direction. (ie - transparent proxies).
Yes, but it could be nice if one could choose, eg.
set filter-policy {in, out, both} or something.
