Subject: Re: MSS clamping proposal
To: Darren Reed <darrenr@reed.wattle.id.au>
From: Todd Vierling <tv@wasabisystems.com>
List: tech-kern
Date: 03/13/2002 17:43:39
On Thu, 14 Mar 2002, Darren Reed wrote:

: > Or is there a way to do this so the entire /28 gets covered
: > in one entry, without rewriting any addresses or ports?
:
: map foo0 12.34.77.0/28 -> 0/0 mssclamp 1452

This method of specifying a non-rewriting NAT rule is not documented at all.

(Nor is, of course, the ability to specify "0/32" as destination address to
auto-pick the interface's address as a single external IP for rewriting.)

ipnat(5) has some huge gaps, when it comes down to it.  "bimap", for
instance, is completely undocumented except for a one-line overview of its
general concept.  (/usr/share/examples/ipf doesn't count as documentation,
because those are even more confusing in many cases.)

: (you should be on icb asking about this!)

See previous reference to "documented".  I wanted to make sure that anyone
else in my situation would know how to do this.  8-)

-- 
-- Todd Vierling <tv@wasabisystems.com>  *  Wasabi & NetBSD:  Run with it.
-- CDs, Integration, Embedding, Support -- http://www.wasabisystems.com/