On 6/1/06, Molle Bestefich <[EMAIL PROTECTED]> wrote:
Hi guys
I've talked to three people now, and like me they can see only one
lonely use case for per-interface rules: anti-spoofing.
Seeing as anti-spoofing is largely automated in pfSense and m0n0wall,
is there any compelling reason for this odd division of the rulebase?
It makes the rules hard to work with, because in addition to deciding
on your source, destination and service, you have to either add your
rule to all of the interfaces, or try to figure out by what arcane
metric the firewall decides when to enforce the rules that are added
under one particular interface and when it's the rules associated with
another interface that's in action.
I'm not sure I see that as a hassle. I'd be more surprised when a
rule matched on an interface I wasn't expecting it to match on. And
anti-spoofing is _not_ automated...the antispoof rules/syntax only
protect the firewalls interfaces itself, not networks behind it.
--Bill
---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]