https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=268717

--- Comment #28 from d...@rabson.org ---
(In reply to Kristof Provost from comment #27)
This is another reason for being conditional on the sysctl. I am open to
alternative suggestions for this but I think we do need to treat the hand-off
to local L4+ processing as a potential filtering event.

I think that Linux iptables make this clearer, allowing filters to register for
NF_INET_LOCAL_IN or NF_INET_LOCAL_OUT specifically.

-- 
You are receiving this mail because:
You are the assignee for the bug.

Reply via email to