If you set say 192.168.64.7/24 on a rule, And the mask is applied to the ip in packet bot not on rule ip too. It just compares the ip field of the address set on rule to the ip in packet (which is masked). Instead of also applying the mask with the 192.168.64.7 so we can be comparing only the network field. So pass 192.168.64.7/24 on a rule never matches any packet(even if it is in the 192.168.64 subnet) . Because only the network field will be in comparison against the whole network + host field on the one set on rule.
Emmanuel |