NetBSD-Bugs archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
Re: kern/52074: -current npf map directive broken
The following reply was made to PR kern/52074; it has been noted by GNATS.
From: Martin Husemann <martin%duskware.de@localhost>
To: Joerg Sonnenberger <joerg%bec.de@localhost>
Cc: gnats-bugs%NetBSD.org@localhost
Subject: Re: kern/52074: -current npf map directive broken
Date: Thu, 11 May 2017 14:51:51 +0200
On Thu, May 11, 2017 at 02:19:49PM +0200, Joerg Sonnenberger wrote:
> On Thu, May 11, 2017 at 10:47:28AM +0100, Roy Marples wrote:
> > I agree with Robert, we shouldn't be sending packets on the wire from an
> > address we don't own.
>
> That depends. The transparent proxy case is tricky in this regard...
I wonder if we should just tag the mbufs as "authorized" somehow if
they come via a packet filter and have been NATed.
Martin
Home |
Main Index |
Thread Index |
Old Index