summaryrefslogtreecommitdiff
path: root/share/man/man5
diff options
context:
space:
mode:
authorRyan Thomas McBride <mcbride@cvs.openbsd.org>2006-10-06 10:45:45 +0000
committerRyan Thomas McBride <mcbride@cvs.openbsd.org>2006-10-06 10:45:45 +0000
commit216eb1494d83e003e2c570f0b053fe6d4a871455 (patch)
tree1e85513e7a98a8c2a24153479bc1110cf236ac53 /share/man/man5
parent59320a567993df86c2a916ba46a3e498a1dc7ddc (diff)
Make 'flags S/SA keep state' the implicit for filter rules, based on
a suggestion from dhartmei@. Also add 'flags any' and 'no state' options to disable flag matching and stateful filtering respectively. IMPORTANT NOTE: Current rulesets will continue to load, but the behaviour may be slightly changed as these defaults are more restrictive. If you are purposefully filtering statelessly ('no state') or have a requirement to create states on intermediate packets ('flags any') you should update your ruleset to make use of the new keywords to explicitly request the behaviour. Note that creation of states from intermediate packets in a connection is not recommended, and will increasingly cause problems as more OSs enable window scaling and increase buffer sizes by default. ok dhartmei@ deraadt@ henning@
Diffstat (limited to 'share/man/man5')
0 files changed, 0 insertions, 0 deletions