Greetings,The inclusion of defined parameters should be a boon for tailoring firewall parameters. It seems, though, that there is a peculiar limitation
define to = 5s set hosts { type ipv4_addr flags timeout timeout $to } The nft tool complains about the presence of the $ in the timeout line. Cheers -- /Marc Oscar Singer/ *Woollysoft* +1.206.328.1718