pfctl has an ruleset optimizer built in, which handles most of that.

So, it is best if you write rules in a way that makes sense.


Lars Bonnesen <[email protected]> wrote:

> Is it no longer important to group block/pass in/out for speed optimization?
> 
> I see many "modern" pf.conf where everything is mixed more or less randomly
> 
> Regards, Lars.

Reply via email to