Re: Complex ruleset questions

This is a discussion on Re: Complex ruleset questions within the IPFilter forums, part of the System Security and Security Related category; Le 2003-06-27, Damian Gerow écrivait : > Hmmmm.... It'll work in theory, It'll work in practice as ...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 06-27-2003
Thomas Quinot
 
Posts: n/a
Default Re: Complex ruleset questions

Le 2003-06-27, Damian Gerow écrivait :

> Hmmmm.... It'll work in theory,


It'll work in practice as well, I have used this pattern succesfully for
years as part of some complex rulesets.

> specifying the allow rules twice, but means that any rule insertions between
> the 'skip' rules and the 'head' rule will break the skips. :(


But there is no reason to insert anything between the skips, they
notionally are part of the same single high-level operation consisting
in branching into a group when any one in a set of predicates matches.
Think of it the way a compiler would generate code for a complex boolean
expression using a combination of elementary tests and jumps.

Thomas.

--
Thomas.Quinot@Cuivre.FR.EU.ORG
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 08:19 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0