Re: Filtering out spoofed network addresses

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Tue, Jul 01, 2003 at 09:32:53PM +0200, Martin Josefsson wrote:

> > > Hi folks,
> > 
> > Hi James,
> > 
> > Indeed, you cannot do this with netfilter. Netfilter does not provide you
> > with the "don't care bits" as cisco calls it.
> 
> What's wrong with:
> 
> -s 0.0.0.0/0.0.255.255

Yes. Just tried it and it worked. Excellent! So the mask is just an arbitrary
mask. Thanks for pointing that out :-) I have to go and redo lots of rules
that I made under a false assumption...

Ramin

> ?
> 
> -- 
> /Martin


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux