All of lore.kernel.org
 help / color / mirror / Atom feed
* Why is ipset nethash set type limited to /31?
@ 2006-03-10  3:36 Menno Smits
  2006-03-10  8:15 ` Jozsef Kadlecsik
  0 siblings, 1 reply; 7+ messages in thread
From: Menno Smits @ 2006-03-10  3:36 UTC (permalink / raw)
  To: netfilter

Hi all,

Is there a reason why the ipset's nethash set type can't be used with
single IPs (/32) as well as larger networks? I'd really like to be able
to use networks and IPs in the same set.

Regards,
Menno


Scanned by the NetBox from NetBox Blue
(http://netboxblue.com/)



^ permalink raw reply	[flat|nested] 7+ messages in thread
* Re: Why is ipset nethash set type limited to /31?
@ 2006-03-10  4:24 Randy Grimshaw
  0 siblings, 0 replies; 7+ messages in thread
From: Randy Grimshaw @ 2006-03-10  4:24 UTC (permalink / raw)
  To: netfilter, menno

<><Randall Grimshaw
Room 203 Machinery Hall
Syracuse University
Syracuse, NY   13244
315-443-5779
rgrimsha@syr.edu
>>> Menno Smits <menno@netboxblue.com> 03/09/06 10:36 PM >>>
> Is there a reason why the ipset's nethash set type can't be used with
> single IPs (/32) as well as larger networks? I'd really like to be able
> to use networks and IPs in the same set.

you cannot have a legitimate network with only one address. you also need a network address (x.x.x.0) and a broadcast address (x.x.x.3) and two addresses for the communicating systems to use (x.x.x.1 and x.x.x.2)

Mircosoft windows and other OS's also enforce this so a /32 isn't practical.....   but...

I understand your idea though, I needed to define several nearly duplicate rules for NET and IP hashes in our gateway application. Fortunately the cost is minimal compared to the overall efficiency gained by using IPset. (A fabulous tool that needs to become mainstream).

<><Randy



^ permalink raw reply	[flat|nested] 7+ messages in thread
[parent not found: <s410b957.066@gwia201.syr.edu>]

end of thread, other threads:[~2006-03-14  9:22 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-03-10  3:36 Why is ipset nethash set type limited to /31? Menno Smits
2006-03-10  8:15 ` Jozsef Kadlecsik
2006-03-12 22:47   ` Menno Smits
2006-03-14  9:22     ` Jozsef Kadlecsik
  -- strict thread matches above, loose matches on Subject: below --
2006-03-10  4:24 Randy Grimshaw
     [not found] <s410b957.066@gwia201.syr.edu>
2006-03-10  7:13 ` Menno Smits
2006-03-10 13:33   ` Jozsef Kadlecsik

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.