On 5/9/05, jared r r spiegel <[EMAIL PROTECTED]> wrote:

>   it feels to me that pf is built from the ground up to be last-match,
>   with a maximized possibility to function in a first-match context.

It's missing the GOTO functionality of many (some?) first-match
firewalls. That might cause some problems in some decision making
paths where one tries to write an all-quick ruleset. (I'm thinking
back to a ipfw system I once had with 5000 rules to do traffic
counting).

-- 
Jon Simola
Systems Administrator
ABC Communications

Reply via email to