On 6/1/06, Bill Marquette <[EMAIL PROTECTED]> wrote:
On 6/1/06, Molle Bestefich <[EMAIL PROTECTED]> wrote:
> Hi guys
>
> I've talked to three people now, and like me they can see only one
> lonely use case for per-interface rules: anti-spoofing.
>
> Seeing as anti-spoofing is largely automated in pfSense and m0n0wall,
> is there any compelling reason for this odd division of the rulebase?
>
> It makes the rules hard to work with, because in addition to deciding
> on your source, destination and service, you have to either add your
> rule to all of the interfaces, or try to figure out by what arcane
> metric the firewall decides when to enforce the rules that are added
> under one particular interface and when it's the rules associated with
> another interface that's in action.

I'm not sure I see that as a hassle.  I'd be more surprised when a
rule matched on an interface I wasn't expecting it to match on.  And
anti-spoofing is _not_ automated...the antispoof rules/syntax only
protect the firewalls interfaces itself, not networks behind it.

I agree with Bill.   Not to mention we inherited this behavior from m0n0wall.

In addition, why are you cross posting between m0n0wall and pfSense
lists?   This is surely not a good idea.

---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to