tech-net archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: MSS clamping in NPF



Egerváry Gergely <gergely%egervary.hu@localhost> wrote:
> ...
> 
> And that's all! MTU and MSS has nothing to do with filter rules.
> They are related to the specific interface.

I agree that that MSS clamping would often be per interface.


> #1) Implement `scrub' as in PF
> (Normalization will be independent from filter rules)
> 
> #2) Implement `match` as in newer PF releases
> (Normalization is done with special filter rules that does not stop
> processing other filter rules)
> 
> ... or, any better ideas?

I am thinking to implement the equivalent of "match" functionality.
Internally, a group is just a rule, so it could have rule procedures
associated as well.

-- 
Mindaugas


Home | Main Index | Thread Index | Old Index