tech-net archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
Re: MSS clamping in NPF
Egerváry Gergely <gergely%egervary.hu@localhost> wrote:
> ...
> 
> And that's all! MTU and MSS has nothing to do with filter rules.
> They are related to the specific interface.
I agree that that MSS clamping would often be per interface.
> #1) Implement `scrub' as in PF
> (Normalization will be independent from filter rules)
> 
> #2) Implement `match` as in newer PF releases
> (Normalization is done with special filter rules that does not stop
> processing other filter rules)
> 
> ... or, any better ideas?
I am thinking to implement the equivalent of "match" functionality.
Internally, a group is just a rule, so it could have rule procedures
associated as well.
-- 
Mindaugas
Home |
Main Index |
Thread Index |
Old Index