Re: net.inet.ip.fw.dyn_keep_states (was: ipfw managing rules - best practice?)

2018-10-25 Thread Andrey V. Elsukov
On 25.10.2018 12:09, Ole wrote: > So do you think the bug is only related to 'setup' and not to 'keep-state' > rules? Or is this just a coincidence? > Im reloading rules now for 1h each minute, and a ssh connection is still > stable. Hi, I think you do not quite understand how it works :)

net.inet.ip.fw.dyn_keep_states (was: ipfw managing rules - best practice?)

2018-10-25 Thread Ole
Wed, 24 Oct 2018 21:42:00 +0300 - "Andrey V. Elsukov" : > On 24.10.2018 19:22, Ole wrote: > > # ipfw -d list > > (...) > > 01510 allow tcp from any to xx.xx.xx.xx 6514 out via epair0b setup > > keep-state :default (...) > > ## Dynamic rules (1 152): > > 01510 STATE tcp yy.yy.yy.yy 54451 <->