Linux Netfilter discussions
 help / color / mirror / Atom feed
From: "Trever L. Adams" <tadams-lists@myrealbox.com>
To: Jozsef Kadlecsik <kadlec@blackhole.kfki.hu>
Cc: netfilter@lists.netfilter.org
Subject: Re: ipv6 and state matching
Date: 25 Mar 2003 10:53:17 -0500	[thread overview]
Message-ID: <1048607597.1052.9.camel@localhost.localdomain> (raw)
In-Reply-To: <Pine.LNX.4.33.0303250926560.7010-100000@blackhole.kfki.hu>

On Tue, 2003-03-25 at 03:33, Jozsef Kadlecsik wrote:
> On 24 Mar 2003, Trever L. Adams wrote:
> 
> > I am unable to find any questions about this.  I really love state
> > matching in ipv4.  I find that w/ RedHat 8.0 and Phoebe (8.1.99 or
> > something like that), that I cannot do this.  This does indeed seem to
> > be an accurate state.
> 
> Brad Chapman had an attempt to port IPv4 conntrack to IPv6 but his code
> was never accepted.
> 
> Last year I worked on the prototype of an unified conntrack code, but it
> was never released. Unfortunately just conntrack doesn't seem to be enough
> - one is tempted to implement NAPT etc. as well.
> 

What is NAPT? Do you mean NAT?  Why was yours never released?

> > Are there plans on doing state support?  Is it all that much more
> > difficult?
> 
> A straight porting is not so difficult, but that direction cannot be
> followed because it would result in a severe code-duplication.
> Unification takes a lot of time.
> 
> Best regards,
> Jozsef

Hmm, what is the desired route right now?  Are they wanting to just
share code base (lots of ifdefs all over) or are they wanting to
actually have the two code bases use the same binary object?

If one object is desired, can you just use ipv6 structs (whatever ones
are involved) in all cases, or should there be a flag and use pointers
so that each connection uses the appropriate structres?

I am willing to give this a go, I think.  However, this would be my
first "major" work in the kernel (I have only helped a bit with cipe
before).  I am not sure how great it would be.

Trever Adams
--
"There's no such things as guaranteed return on anything these days." --
John S. Demott



  parent reply	other threads:[~2003-03-25 15:53 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-03-24 20:08 ipv6 and state matching Trever L. Adams
2003-03-25  8:33 ` Jozsef Kadlecsik
2003-03-25 13:08   ` Microsoft PPTP VPN server behind FIREWALL Remus
2003-03-25 15:22     ` Ilguiz Latypov
2003-03-25 17:37     ` Rowan Reid
2003-03-25 18:34       ` bill davidsen
2003-03-25 15:53   ` Trever L. Adams [this message]
2003-03-25 23:33     ` ipv6 and state matching Jozsef Kadlecsik

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1048607597.1052.9.camel@localhost.localdomain \
    --to=tadams-lists@myrealbox.com \
    --cc=kadlec@blackhole.kfki.hu \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox