cvs commit: src/sbin/ipfw ipfw.8 ipfw2.c src/sys/netinet in.h ip_fw.h ip_fw2.c raw_ip.c

Darren Reed darrenr at hub.freebsd.org
Thu Jun 10 07:12:29 GMT 2004


On Thu, Jun 10, 2004 at 09:53:35AM +0300, Ruslan Ermilov wrote:
> On Thu, Jun 10, 2004 at 03:27:01AM +0000, Darren Reed wrote:
> > On Thu, Jun 10, 2004 at 04:45:37AM +0200, Max Laier wrote:
> > > On Wednesday 09 June 2004 22:10, Ruslan Ermilov wrote:
> > > > ru          2004-06-09 20:10:38 UTC
> > > >
> > > >   FreeBSD src repository
> > > >
> > > >   Modified files:
> > > >     sbin/ipfw            ipfw.8 ipfw2.c
> > > >     sys/netinet          in.h ip_fw.h ip_fw2.c raw_ip.c
> > > >   Log:
> > > >   Introduce a new feature to IPFW2: lookup tables.  These are useful
> > > >   for handling large sparse address sets.  Initial implementation by
> > > >   Vsevolod Lobko <seva at ip.net.ua>, refined by me.
> > > 
> > > Idea from: pf ;)
> > > Nice!
> > 
> > Both ipfilter & iptables supported this kind of address matching before
> > pf did.
> > 
> How is it possible with IPFilter, can you enlighten me?

In IPFilter4, there's a program called ippool that manages "it" and
subsequent support within the rest of the code.

http://coombs.anu.edu.au/~avalon/ip-filter.html

Darren


More information about the cvs-src mailing list