Subject: Re: stf and NAT
To: None <tech-net@netbsd.org>
From: Rodolphe De Saint Leger <rdesaintleger@gmail.com>
List: tech-net
Date: 07/21/2007 18:23:35
On 7/18/07, Zafer Aydogan <zafer@aydogan.de> wrote:
> >
> Looks good.
> Can you please write a patch for current.
> Thanks, Zafer.
>

Here is (almost) the same patch for current,

http://82.67.230.130/strict/current/cpatch.diff
http://82.67.230.130/strict/current/if_stf.c

I added another option (strict checking of 6to4 traffic) and ingress
filtering for ipv6 addresses.

I made some tests, it seems to work.
Any comments ?

Could it be commited to head ?

Regards

-- 
There is currently insufficient research to definitively conclude that
unix overuse is an addiction.