Re: [PATCH|RFC] IPv6 netfilter: a module for complete proxy ND support
From: Harald Welte <hidden>
Date: 2004-01-17 11:33:58
Also in:
netfilter-devel
Attachments
- signature.asc [application/pgp-signature] 189 bytes
From: Harald Welte <hidden>
Date: 2004-01-17 11:33:58
Also in:
netfilter-devel
On Wed, Jan 14, 2004 at 09:04:27PM +0900, YOSHIFUJI Hideaki / ?$B5HF#1QL@ wrote:
In article [ref] (at Wed, 14 Jan 2004 13:25:42 +0200 (EET)), Ville Nuorvala [off-list ref] says:quoted
the packets for local processing. I think the cleanest solution for this is a netfilter module (which I have incidentally written already :)I don't think so. Proxy should not depend on netfilter.
Where is the problem? It doesn't depend on hevyweight functions like iptables/conntrack/whatever... it just depends on the netfilter hooks in the core network stack (which are very lightweight, compared to what the rest of the packet filtering subsystem does).
--yoshfuji
-- - Harald Welte [off-list ref] http://www.netfilter.org/ ============================================================================ "Fragmentation is like classful addressing -- an interesting early architectural error that shows how much experimentation was going on while IP was being designed." -- Paul Vixie