From: Menno Smits <menno@netboxblue.com>
To: Netfilter Mailing list <netfilter@lists.netfilter.org>
Subject: Re: Why is ipset nethash set type limited to /31?
Date: Fri, 10 Mar 2006 17:13:39 +1000 [thread overview]
Message-ID: <44112723.30505@netboxblue.com> (raw)
In-Reply-To: <s410b957.066@gwia201.syr.edu>
Hi Randy,
Randy Grimshaw wrote:
> you cannot have a legitimate network with only one address. you also
> need a network address (x.x.x.0) and a broadcast address (x.x.x.3)
> and two addresses for the communicating systems to use (x.x.x.1 and
> x.x.x.2)
>
> Mircosoft windows and other OS's also enforce this so a /32 isn't
> practical..... but...
>
> I understand your idea though, I needed to define several nearly
> duplicate rules for NET and IP hashes in our gateway application.
> Fortunately the cost is minimal compared to the overall efficiency
> gained by using IPset. (A fabulous tool that needs to become
> mainstream).
I understand networks, network addresses and broadcast addresses however
it would be useful to be able to match against both IP addresses and
networks with the one set. Why can't an IP address just be treated as a
/32 "network"?
The fact that you've had to work around te same limitation indicates
that I'm not the only one who could benefit from something like this. Is
there a technical reason why this isn't possible?
On a side note, I agree that IPset is fabulous and should be part of
mainline netfilter. It can greatly simplify otherwise complex firewall
configurations.
Menno
Scanned by the NetBox from NetBox Blue
(http://netboxblue.com/)
next parent reply other threads:[~2006-03-10 7:13 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <s410b957.066@gwia201.syr.edu>
2006-03-10 7:13 ` Menno Smits [this message]
2006-03-10 13:33 ` Why is ipset nethash set type limited to /31? Jozsef Kadlecsik
2006-03-10 4:24 Randy Grimshaw
-- strict thread matches above, loose matches on Subject: below --
2006-03-10 3:36 Menno Smits
2006-03-10 8:15 ` Jozsef Kadlecsik
2006-03-12 22:47 ` Menno Smits
2006-03-14 9:22 ` Jozsef Kadlecsik
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=44112723.30505@netboxblue.com \
--to=menno@netboxblue.com \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.