Re: State table with a rule change

2002-12-12 Thread Daniel Hartmeier
On Thu, Dec 12, 2002 at 05:53:52PM +0200, Can Erkin Acar wrote: > Rule changes do not affect existing states. You have to process each > state and decide if you still want it or not. Look at authpf for one > way to do it. authpf removes states containing the IP address > of the connection it authe

Re: State table with a rule change

2002-12-12 Thread Can Erkin Acar
Rule changes do not affect existing states. You have to process each state and decide if you still want it or not. Look at authpf for one way to do it. authpf removes states containing the IP address of the connection it authenticated on exit. Can On Thu, Dec 12, 2002 at 08:11:27AM -0700, Larry C

State table with a rule change

2002-12-12 Thread Larry Coulson
If pf has been in operation for a while and a new rule set is loaded what happens to the states? For example there could be two rules to allow packets (rule A & rule B) in the old rule set that have just created two tcp established states (state A & state B) that could naturally time out in 24