Re: [PATCH] chaostables

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Amin Azez
Date: Friday, March 9, 2007 - 4:54 am

* Jan Engelhardt wrote, On 09/03/07 10:19:
For the record, I support inclusion of this extension in general.
It is true to say "but a netfilter guru could craft together a sequence
of mark-consuming rules to do something somewhat similar" the same is
also somewhat true for connlimit (packet limits) and so on. The point of
this match is that people don't have to.
I understand what you say but it sounds a bit like saying: "but we
didn't make it very good because so few people would use it anyway"
which of course makes it even less attractive. I realise you have your
own interpretation but this is how it reads to me.
...
I guessed as much. I use it heavily, with my xml rule generators.
There's too many things fighting over the same few bits of the mark, and
in your case you are using it to track internal state of a connection
that has no relevance to the rest of the iptables/ebtables rules.

I'm suggesting that some of the people who would want to use the chaos
match, won't because of the mark issue.

This is not a new problem.

http://article.gmane.org/gmane.comp.security.firewalls.netfilter.devel/16217
<http://news.gmane.org/find-root.php?message_id=%3c44AEFE20.3020307%40shorewall.net%3e>


I suggested one solution
http://article.gmane.org/gmane.comp.security.firewalls.netfilter.devel/16244

and Patrick McHardy has suggested using ct_extend.

I've not looked into this further because I'm too busy doing xml
versions of iptables, ebtables, iproute anc tc.

[There's an ip route<->xml at:
http://mailman.ds9a.nl/pipermail/lartc/2007q1/020376.html
iptables now has xml<-> convertor ]

Sam
-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[PATCH] chaostables, Jan Engelhardt, (Wed Mar 7, 11:35 pm)
Re: [PATCH] chaostables, Patrick McHardy, (Thu Mar 8, 5:59 am)
Re: [PATCH] chaostables, Alan Cox, (Thu Mar 8, 6:14 am)
Re: [PATCH] chaostables, James Morris, (Thu Mar 8, 7:55 am)
Re: [PATCH] chaostables, Jan Engelhardt, (Thu Mar 8, 9:39 am)
Re: [PATCH] chaostables, Patrick McHardy, (Thu Mar 8, 10:15 am)
Re: [PATCH] chaostables, Alan Cox, (Thu Mar 8, 11:14 am)
Re: [PATCH] chaostables, Jan Engelhardt, (Thu Mar 8, 1:26 pm)
Re: [PATCH] chaostables, Jan Engelhardt, (Fri Mar 9, 12:54 am)
Re: [PATCH] chaostables, jimmy, (Fri Mar 9, 1:07 am)
Re: [PATCH] chaostables, Amin Azez, (Fri Mar 9, 2:35 am)
Re: [PATCH] chaostables, Jan Engelhardt, (Fri Mar 9, 3:19 am)
Re: [PATCH] chaostables, Amin Azez, (Fri Mar 9, 4:54 am)
Re: [PATCH] chaostables, Petr , (Fri Mar 9, 9:23 am)
Re: [PATCH] chaostables, Jan Engelhardt, (Fri Mar 9, 10:30 am)