Tue May 10, 2005 10:12 am
Thanks Eugene. The explanations and examples here are much better than previous documentation. This is very similar to rules I was using already but I seemed to remember that in previous tests we found that each active connection was treated separately and that a user with many active connections could easily exceed his limit. Perhaps that was because I was previously using 0.0.0.0 for src and dst addresses instead of being network specific?