On Mon, 07 Aug 2006, Kjetil Torgrim Homme wrote: > I think David is missing the issue: it's the proxied connection which is > problematic, not the connection to the client. this locks the IP > addresses to the frontend's and the backend's, and the port on the > backend side is always 143 (or whatever you prefer), so the only > variable part of the tuple is the port number on the frontend. this > restricts a frontend to 65k connections to each backend. Not if the two hosts are capable of TCP timestamps, AFAIK. -- "One disk to rule them all, One disk to find them. One disk to bring them all and in the darkness grind them. In the Land of Redmond where the shadows lie." -- The Silicon Valley Tarot Henrique Holschuh ---- Cyrus Home Page: http://asg.web.cmu.edu/cyrus Cyrus Wiki/FAQ: http://cyruswiki.andrew.cmu.edu List Archives/Info: http://asg.web.cmu.edu/cyrus/mailing-list.html