[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: motivation behind the quick

On Thu, May 15, 2003 at 06:42:48PM +0100, Dom De Vitto wrote:

> - block unless specifically permitted
> - permit unless specifically blocked

Hear, hear. You can have a  default deny without quick, of course,
but there  are times when it's  simpler and easier (for  the human
being,  and pf  is so  fast I  don't give  a damn  about what  the
computer thinks) to construct a good ruleset with quick.

But that's  why it's  an *option.* Some  people like  first match;
others like last-match; still more  like both. Choice is good. use
what fits you best.



Ben Goren

[demime 0.98d removed an attachment of type application/pgp-signature]