diff --git a/en_US.ISO8859-1/books/handbook/firewalls/chapter.sgml b/en_US.ISO8859-1/books/handbook/firewalls/chapter.sgml index 6ad62c79e3..857d549f0f 100644 --- a/en_US.ISO8859-1/books/handbook/firewalls/chapter.sgml +++ b/en_US.ISO8859-1/books/handbook/firewalls/chapter.sgml @@ -2193,6 +2193,7 @@ options IPV6FIREWALL_DEFAULT_TO_ACCEPT rule processing order + When a packet enters the firewall it is compared against the first rule in the rule set and progress one rule at a time moving from top to bottom of the set in ascending rule number @@ -2205,6 +2206,12 @@ options IPV6FIREWALL_DEFAULT_TO_ACCEPT packets and discards them without any reply back to the originating destination. + + The search continues after count, + skipto and tee + rules. + + The instructions contained here are based on using rules that contain the stateful 'keep state', 'limit', 'in'/'out', and via options. This is the basic framework for coding an