Well, I think netfilter blows away ACLs in IOS standard, for one netfilter is stateful, and a ACL cannot do the chains like iptables can so it has to be processed from top to bottom every time. I've never used Cisco IOS firewall version, so I can't compared to that.
|