[pve-devel] [PATCH] add ips feature v5

Dietmar Maurer dietmar at proxmox.com
Thu Mar 20 08:02:47 CET 2014


> But isn't it slower (more taps(in|out) to check), than simply use
> 
> -m conntrack --ctstate RELATED,ESTABLISHED -j PVE-Accept  at the begin of
> FORWARD ?

Maybe, but still faster than -j PVEFW-Accept?

And we only need to do that when ips is enabled.


More information about the pve-devel mailing list