Re: CONFIG_NETFILTER_ADVANCED

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi Patrick,

On Sun, 18 Nov 2007, Patrick McHardy wrote:

> For people who want to compile-test them all (like me), we
> still can have a CONFIG_NETFILTER_ALL option hidden under
> CONFIG_NETFILTER_ADVANCED for simplicity, but that is a
> different topic.

I think the other way around would be better:

CONFIG_NETFILTER		enable everyting
CONFIG_NETFILTER_WITHOUT_NAT	everything except NAT
CONFIG_NETFILTER_ADVANCED	select modules manually

This is more or less the most usual cases: typically almost everyone wants 
NAT and the wide range of matches and targets. Some places don't use NAT. 
And if someone wants to exclude modules or disable settings like 
conntrack flow accounting, in advanced mode it'd be possible to do so.

Best regards,
Jozsef
-
E-mail  : kadlec@xxxxxxxxxxxxxxxxx, kadlec@xxxxxxxxxxxxxxx
PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt
Address : KFKI Research Institute for Particle and Nuclear Physics
          H-1525 Budapest 114, POB. 49, Hungary
-
To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html

[Index of Archives]     [Netfitler Users]     [LARTC]     [Bugtraq]     [Yosemite Forum]

  Powered by Linux