Date: Sun, 18 May 2003 02:23:29 +0200 From: "Simon L. Nielsen" <simon@nitro.dk> To: "Gregory P. Smith" <greg@electricrain.com> Cc: freebsd-net@freebsd.org Subject: Re: matching a range of iplens with ipfw2? Message-ID: <20030518002328.GJ399@nitro.dk> In-Reply-To: <20030517195354.GF13501@zot.electricrain.com> References: <20030517195354.GF13501@zot.electricrain.com>
next in thread | previous in thread | raw e-mail | index | archive | help
--DSayHWYpDlRfCAAQ Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On 2003.05.17 12:53:54 -0700, Gregory P. Smith wrote: > Is there a way to match a range of iplen values in an ipfw2 rule? > (say i wanted a rule to match all tcp packets <=3D 64 bytes). At the moment no. I implemented a simple version of it some time ago but since it was not "the right way" (not flexible enough.. try searching the archives for FreeBSD-ipfw for more details) I didn't proceed any further with my patch but it should work just fine. My patch can be found at http://simon.nitro.dk/freebsd/files/ipfw2-iplen.patch if you want to try it out. Somebody (sorry can't remeber who) was looking into implemented iplen ranges "the right way" as sugested by Luigi Rizzo, but I don' know the progress of that work. --=20 Simon L. Nielsen --DSayHWYpDlRfCAAQ Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (FreeBSD) iD8DBQE+xtKA8kocFXgPTRwRArAEAJwKsizYdpMmXdy6oX3dEJWTsYS9OQCg0kfZ KL/fJIBa2f02MT9YZrCLF2M= =s/HM -----END PGP SIGNATURE----- --DSayHWYpDlRfCAAQ--
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20030518002328.GJ399>