How to PF Firewall Ruleset Optimization

by on September 28, 2006 · 0 comments· Last updated September 28, 2006

OpenBSD journal has published excellent PF Firewall Ruleset Optimization tutorial.

From the article:
"This is the first installment in a series of three articles about PF. I originally wrote them as chapters for a book, but then publication was cancelled. Luckily, the rights could be salvaged, and now you get to enjoy them as undeadly.org exclusives."

Firewall Ruleset Optimization topics:

  • Goals
  • The significance of packet rate
  • When pf is the bottleneck
  • Filter statefully
  • The downside of stateful filtering
  • Ruleset evaluation
  • Ordering rulesets to maximize skip steps
  • Use tables for address lists
  • Use quick to abort ruleset evaluation when rules match
  • Anchors with conditional evaluation
  • Let pfctl do the work for you
  • Testing Your Firewall (read)
  • Firewall Management (upcoming)

Read more at OpenBSD journal...



You should follow me on twitter here or grab rss feed to keep track of new changes.

Featured Articles:

{ 0 comments… add one now }

Leave a Comment

You can use these HTML tags and attributes for your code and commands: <strong> <em> <ol> <li> <u> <ul> <blockquote> <pre> <a href="" title="">
What is 14 + 6 ?
Please leave these two fields as-is:
Solve the simple math so we know that you are a human and not a bot.



Previous post:

Next post: