logoalt Hacker News

wahernyesterday at 7:38 PM1 replyview on HN

That particular change improves throughput received locally. Though over the past few years there's been a ton of work on unlocking the network layer generally to support more parallelism.

For a firewall I guess the critical question is the degree of parallelism supported by OpenBSD's PF stack, especially as it relates to common features like connection statefulness, NAT, etc.


Replies

SoftTalkeryesterday at 7:57 PM

Thanks. Yes after I posted that I started wondering if it was really relevant to pf.