1

It's not clear to me if the check for INVALID vs ESTABLISHED,RELATED is equally fast for both cases (and if the states are completely orthogonal) Do I have to drop INVALID before accepting ESTABLISHED or can I safely accept ESTABLISHED and then drop INVALID?

1
  • Doesn't matter in the grand scheme of things but I've always had it the last. Commented Apr 7, 2024 at 19:14

1 Answer 1

1

Logically the state INVALID should be mutually exclusive with any of ESTABLISHED, RELATED and NEW.

I can't give you throughput measurements. All I can say is that since a packet can only be in precisely one of the four states you won't end up accepting invalid packets unless you have a catch-all rule of ACCEPT. Drop them early and then there's no need to worry about them.

Personally I would drop INVALID as early in the chain as possible.

You must log in to answer this question.

Start asking to get answers

Find the answer to your question by asking.

Ask question

Explore related questions

See similar questions with these tags.