Subject: Re: MSS clamping proposal
To: Todd Vierling <tv@wasabisystems.com>
From: Darren Reed <darrenr@reed.wattle.id.au>
List: tech-kern
Date: 03/14/2002 09:49:01
In some email I received from Todd Vierling, sie wrote:
> On Thu, 14 Mar 2002, Darren Reed wrote:
>
> : > Or is there a way to do this so the entire /28 gets covered
> : > in one entry, without rewriting any addresses or ports?
> :
> : map foo0 12.34.77.0/28 -> 0/0 mssclamp 1452
>
> This method of specifying a non-rewriting NAT rule is not documented at all.
>
> (Nor is, of course, the ability to specify "0/32" as destination address to
> auto-pick the interface's address as a single external IP for rewriting.)
>
> ipnat(5) has some huge gaps, when it comes down to it. "bimap", for
> instance, is completely undocumented except for a one-line overview of its
> general concept. (/usr/share/examples/ipf doesn't count as documentation,
> because those are even more confusing in many cases.)
>
> : (you should be on icb asking about this!)
>
> See previous reference to "documented". I wanted to make sure that anyone
> else in my situation would know how to do this. 8-)
Maybe someone should d/l this file and include it somewhere.
http://www.obfuscation.org/ipf/ipf-howto.txt
So, when will you be sending patches for the man pages to update the docs?
Darren