Multiple Address specification or match
Henrik Nordstrom
hno at marasystems.com
Thu Sep 30 13:42:33 CEST 2004
On Thu, 30 Sep 2004, Eric Leblond wrote:
> iptables/netfilter has to be efficient, rules generation script has to
> be elegant. Having 3 rules is as efficient as your masked "or" rules if
> it was coded and 3 separate rules are more simple than your global one
> so in a way this is more elegant.
For hipac this is true, but not really when using iptables.
Regards
Henrik
More information about the netfilter-devel
mailing list