Pardon me if my question is stupid or irrational..

In Checkpoint FW-1 there is only one rulebase against which both incoming and outgoing 
traffic is matched. Instead of this if there were two different rulebases (sets of 
rules) for incoming and outgoing wouldn't it give better performance?

Why is this not there? Or is this the way the policy/rulebase works after compilation?

I think this feature is there in IPChains !!!

Thanks
Sam

_____________________________________________________
Chat with your friends as soon as they come online. Get Rediff Bol at
http://bol.rediff.com

Participate in crazy auctions at http://auctions.rediff.com/auctions/



-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]

Reply via email to