ip filter limitations?
A “real” switch (e.g., the Alteon) can decide where a connection goes when it starts
With the IP filter package, we have to install rules beforehand
Will changing this mapping break existing connections?
- Maybe not; per-connection state may be persistent even when rules change
- If so, use stable hash function ala multicast rendezvous point selection from set