Subject: Re: IPFilter IPv6 configuration
To: None <tech-net@netbsd.org>
From: Rui Paulo <rpaulo@netbsd-pt.org>
List: tech-net
Date: 04/05/2005 15:44:04
On 2005-04-05, Darren Reed <darrenr@NetBSD.org> wrote:
>
> For those that use IPFilter with IPv6 on NetBSD, does the current
> configuration cause any problems for you?
None at all, I'm running ipfilter 4.1.3 under NetBSD/sparc.
>
> Do you edit ipf.conf and forget to edit ipf6.conf or vice verssa?
Sometimes :)
>
> Are there interaction issues or reporting problems needing to
> remember -6?
None, that I'm aware of.
>
> If there was just a single configuration file, ipf.conf, that
> contained all IP (IPv4/6) firewall rules, would this make like
> easier or harder?
Easier, since I've got a lot of rules that are common to both
files.
>
> If you were forced to manually transition your current system
> layout with both ipf.conf and ipf6.conf, would this be a serious
> issue?
Not to me.
>
> One other question, if NAT were to support IPv6 also, would you
> expect a ipnat6.conf or for it to all fit in ipnat.conf?
ipnat.conf would be fine for both ipv4 and ipv6.
>
> Consider, with this, that with ippool, I've decided to use the same
> pool to hold both IPv4/6 addresses.
Guess that will help having only ipf.conf.
--
Rui Paulo <rpaulo@netbsd-pt.org> http://www.netbsd-pt.org/users/rpaulo/