Multiple Address specification or match

Henrik Nordstrom hno at marasystems.com
Thu Sep 30 13:42:33 CEST 2004


On Thu, 30 Sep 2004, Eric Leblond wrote:

> iptables/netfilter has to be efficient, rules generation script has to
> be elegant. Having 3 rules is as efficient as your masked "or" rules if
> it was coded and 3 separate rules are more simple than your global one
> so in a way this is more elegant.

For hipac this is true, but not really when using iptables.

Regards
Henrik



More information about the netfilter-devel mailing list