Subject: session timeout for ipnat
To: None <>
From: Steve Bellovin <>
List: netbsd-users
Date: 02/05/2002 13:43:25
Is there some simple way to change the session timeout for IPnat?
From a quick glance at the code, fr_defnatage is always initialized to 
DEF_NAT_AGE, which (on 1.5.2) is 1200 seconds.  There does not seem to 
be a sysctl to change it, either.

		--Steve Bellovin,
		Full text of "Firewalls" book now at