Re: Filtering out spoofed network addresses

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Tue, 1 Jul 2003, Ramin Dousti wrote:

> > > Indeed, you cannot do this with netfilter. Netfilter does not provide you
> > > with the "don't care bits" as cisco calls it.
> >
> > What's wrong with:
> >
> > -s 0.0.0.0/0.0.255.255
>
> Yes. Just tried it and it worked. Excellent! So the mask is just an arbitrary
> mask. Thanks for pointing that out :-) I have to go and redo lots of rules
> that I made under a false assumption...

Well, I too just applied it and I am delighted to say that it works like a
charm.  Thank you VERY much.

James R. Hay				jrhay@xxxxxxxxxx
Hay-Net Networks
P.O. Box 46051
Pointe Claire, QC
H9R 5R4



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux