Вести с полей

From
Slawa Olhovchenkov (2:5030/500)
To
All
Date
2007-01-02T00:48Z
Area
RU.UNIX.BSD
Hello All!

piso        2006-12-29 21:59:18 UTC

  FreeBSD src repository

  Modified files:
    etc                  rc.firewall
    sbin/ipfw            ipfw.8 ipfw2.c
    sys/netinet          in.h ip_fw.h ip_fw2.c ip_fw_pfil.c
                         raw_ip.c
  Log:
  Summer of Code 2005: improve libalias - part 2 of 2

  With the second (and last) part of my previous Summer of Code work, we get:

  -ipfw's in kernel nat

  -redirect_* and LSNAT support

  General information about nat syntax and some examples are available
  in the ipfw (8) man page. The redirect and LSNAT syntax are identical
  to natd, so please refer to natd (8) man page.

  To enable in kernel nat in rc.conf, two options were added:

  o firewall_nat_enable: equivalent to natd_enable

  o firewall_nat_interface: equivalent to natd_interface

  Remember to set net.inet.ip.fw.one_pass to 0, if you want the packet
  to continue being checked by the firewall ruleset after being
  (de)aliased.

  NOTA BENE: due to some problems with libalias architecture, in kernel
  nat won't work with TSO enabled nic, thus you have to disable TSO via
  ifconfig (ifconfig foo0 -tso).

  Approved by: glebius (mentor)

... Икона IBM должна стоять в синем углу.
--- GoldED+/BSD 1.1.5
 * Origin:  (2:5030/500)
SEEN-BY: 50/12 203 400/814 450/186 1024 451/30 469/418 550/196 4614/20 4635/4
SEEN-BY: 5000/5000 5011/13 5012/46 5015/28 5019/26 5020/154 175 400 545 549
SEEN-BY: 5020/758 1523 1604 1630 2142 2238 2395 2450 2590 2871 4441 5021/3 29
SEEN-BY: 5022/128 5025/3 750 5027/12 5029/32 5030/500 556 966 1080 1900 1957
SEEN-BY: 5030/2828 5031/47 70 5035/38 5040/47 5042/13 5045/7 5049/50 97 5054/1
SEEN-BY: 5054/4 8 9 11 28 35 36 37 45 66 67 70 75 84 85 5059/9 37 5062/1 10
SEEN-BY: 5063/3 5064/7 5076/1 5077/70 5080/80 1003 5082/6 5083/21 5084/9
SEEN-BY: 5085/13 5090/108 5094/4 5095/20 5096/18 5099/11 6001/10
PATH: 5030/500 5020/4441 545 5054/1 37