Thank you Cedrik, took some time to sink in, but sounds reasonable to me. It's quite a bit different from what I had in mind. Let's see how I can sell this concept to my customers IT guy.
Someone is reading it, now you know!
Edit:
One more thing! I know, this question will come, even if a bit off topic: Switching from a classical segmented IP filter (vulgo: firewall) setup to a host based filter, any idea, if and how this impacts overall performance? This is no a huge setup, but has ~200-300 hosts IPs per interface.
Quote from: Monviech (Cedrik) on April 20, 2026, 08:48:29 PMReading the man pages is a good idea, I wrote them :)
Someone is reading it, now you know!
Edit:
One more thing! I know, this question will come, even if a bit off topic: Switching from a classical segmented IP filter (vulgo: firewall) setup to a host based filter, any idea, if and how this impacts overall performance? This is no a huge setup, but has ~200-300 hosts IPs per interface.
"