Hi list,

hy rules:

pass in  quick on $extif ...
pass in  quick on $extif ...
pass out quick on $extif ...
an so on about 100 rules

the order of the rules is optimized
the first rules are the rules with the most
traffic

now a want to do accouting with labels
after this rules i place

pass in  quick on $extif from any to $server1 label "in server1"
pass out quick on $extif from $server1 to any label "out server1"

ok, this doesn't work if i've in my 100 of rules
the quick keyword. if i remove the quick
keyword it works. quick in the label rules are ok.

after removing the quick keywords my optimized
order is unprofitable. each packet will be
evalutate in each rule :-(.

is there a way to optimize this construct ?

My next problem is: After adding or removing some
of my rules in pf.conf and reloading pf with pfctl -f pf.conf
the label statistics will be reset :-(. Is there a way
to reload pf.conf without to untouch the statistics
of existing labels ? (the label rules are not changed).

Thanks !!!!!

Thomas

-- 
Mit freundlichen Gr|_en
Best regards

Thomas Bvrnert
Geschdftsf|hrer
Senior IT Consultant & Manager
BSI lizenzierter ISO27001 Auditor auf Basis IT-Grundschutz

DO NOT GIVE OUR ADDRESS TO THIRD PARTYS, WE HATE JUNK-MAIL
___________________________________________________________________
TBits.net GmbH                  | Telefon:  +49 (0)7172 18391-0
Thomas Bvrnert                  | Telefax:  +49 (0)7172 18391-99
Seeweg 6                        | Service:  +49 (0)700 TBITSNET
D-73553 Alfdorf                 | Auto:     +49 (0)170 6744415
www.tbits.net                   | eMail:    [EMAIL PROTECTED]
Key fingerprint = 8602 2EF5 78FD 3C04 B148  2506 5D4F 6A49 E4E2 9D15

Reply via email to