From owner-freebsd-current@FreeBSD.ORG Wed Mar 3 13:53:35 2004 Return-Path: Delivered-To: freebsd-current@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 9B86F16A4CE for ; Wed, 3 Mar 2004 13:53:35 -0800 (PST) Received: from mailtoaster1.pipeline.ch (mailtoaster1.pipeline.ch [62.48.0.70]) by mx1.FreeBSD.org (Postfix) with ESMTP id BDE6B43D1F for ; Wed, 3 Mar 2004 13:53:34 -0800 (PST) (envelope-from andre@freebsd.org) Received: (qmail 77255 invoked from network); 3 Mar 2004 21:53:33 -0000 Received: from unknown (HELO freebsd.org) ([62.48.0.54]) (envelope-sender ) by mailtoaster1.pipeline.ch (qmail-ldap-1.03) with SMTP for ; 3 Mar 2004 21:53:33 -0000 Message-ID: <404653DB.186DA0C2@freebsd.org> Date: Wed, 03 Mar 2004 22:53:31 +0100 From: Andre Oppermann X-Mailer: Mozilla 4.76 [en] (Windows NT 5.0; U) X-Accept-Language: en MIME-Version: 1.0 To: James References: <4043B6BA.B847F081@freebsd.org> <200403011507.52238.wes@softweyr.com> <20040302031625.GA4061@scylla.towardex.com> <20040302042957.GH3841@saboteur.dek.spc.org> <20040302082625.GE22985@cell.sick.ru> <20040303181034.GA58284@scylla.towardex.com> Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit cc: Wes Peters cc: Gleb Smirnoff cc: freebsd-current@freebsd.org cc: freebsd-net@freebsd.org Subject: Re: My planned work on networking stack X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 03 Mar 2004 21:53:35 -0000 James wrote: > rewriting of routing stack and implementing FIB-like structure as what andre > proposed in this thread is very welcoming. Just wait a few month and then have a look at what I put up. :-) > there are still other things freebsd lacks. such as uRPF that _SERVICE_PROVIDER_ > can use. ipfw2 has verrevpath but all it does from what i know is strict uRPF > only. service providers like myself, if we were to use freebsd boxen to run our > network, i am not spending money on a router that doesn't do loose-check uRPF. > this sounds like something linux does too but i refuse to use that :P That is pretty easy to implement. I should have it by Friday at latest, depends on when exactly I find time for it. ip verify unicast source reachable-via [any|ifn] The ipfw2 command would look like this: ... versrcreach [fxp0] What else is missing in FreeBSD? -- Andre