tech-net archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: merging forwarding & packet filtering?



David Young wrote:
What do people think about gradually merging the packet-forwarding and
packet-filtering functions in the kernel?

Probably the most sensible thing to do is to make it possible for
the inbound filter to return a "hint" about where the kernel should
route the packet and if that hint is null when the kernel gets to doing
the forwarding, then the kernel consults the routing table(s).

Needing or having the firewall do forwarding is ridiculous and a
gross hack. Yes, it works, but that doesn't make it right.

Darren



Home | Main Index | Thread Index | Old Index