hmm, on Mon, Mar 06, 2006 at 07:13:32AM -0500, Mike Frantzen said that
> # pfctl -nvf /etc/pf.conf > /root/orig
> # pfctl -novf /etc/pf.optimized > /root/optimized
                ^^^^^^^^^^^^^^^^^

how do i get this file? :)

this was not tested, was it? :)



thanks for the answers. i generated both the files, and diffed them.
apart from the optimizer moving ipv6 stuff after the ipv4 stuff
no change.  so i am the best optimizer :)))


but one question remains.  i don't have anything in my pf.conf that
would indicate that ipv6 should come first, it doesn't even mention
ipv6 at all, the only place "inet" is used for letting ping in.

so i guess pfctl does ipv6 then ipv4.  but if called with -o, the order
is reversed, ipv4 then ipv6...  is there a reason for this?

-f
-- 
to have a friend you must first be one.

Reply via email to