Subject: Re: IPFilter IPv6 configuration
To: None <tech-net@netbsd.org>
From: Rui Paulo <rpaulo@netbsd-pt.org>
List: tech-net
Date: 04/05/2005 15:44:04
On 2005-04-05, Darren Reed <darrenr@NetBSD.org> wrote:
>
> For those that use IPFilter with IPv6 on NetBSD, does the current
> configuration cause any problems for you?

None at all, I'm running ipfilter 4.1.3 under NetBSD/sparc.

>
> Do you edit ipf.conf and forget to edit ipf6.conf or vice verssa?

Sometimes :)

>
> Are there interaction issues or reporting problems needing to
> remember -6?

None, that I'm aware of.

>
> If there was just a single configuration file, ipf.conf, that
> contained all IP (IPv4/6) firewall rules, would this make like
> easier or harder?

Easier, since I've got a lot of rules that are common to both
files. 

>
> If you were forced to manually transition your current system
> layout with both ipf.conf and ipf6.conf, would this be a serious
> issue?

Not to me.

>
> One other question, if NAT were to support IPv6 also, would you
> expect a ipnat6.conf or for it to all fit in ipnat.conf?

ipnat.conf would be fine for both ipv4 and ipv6.

>
> Consider, with this, that with ippool, I've decided to use the same
> pool to hold both IPv4/6 addresses.

Guess that will help having only ipf.conf.

-- 
 Rui Paulo <rpaulo@netbsd-pt.org>        http://www.netbsd-pt.org/users/rpaulo/