OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Pf Macro Limit/Performance

From: Roy Morris (rmorrisinternetsecure.com)
Date: Fri Jan 02 2004 - 09:22:08 CST


sweet, thanks!

-----Original Message-----
From: Theo de Raadt [mailto:deraadtcvs.openbsd.org]
Sent: Friday, January 02, 2004 10:23 AM
To: miscopenbsd.org; Roy Morris
Subject: Re: Pf Macro Limit/Performance

        I am wondering if there is any practical limit on the amount of macros that
        can be used with PF, and further is there is a 'major' performance hit for
        using them? I have been running pf for quite some time but have never bothered
        with macros until now.

        I should give an example of what I am asking I guess. Using the following
        syntax for say 40 machines, causing 80 entries?

        int_machine_1 = "x.y.z.z"
        ext_machine_1 = "x.x.x.x"

They are parse-time only. Free.