> But the NAT makes the IPChains in Linux statefull, since it knows how
> to handle fragmentation, window and syn/ack tracking.

yup, it does feel like a kludge though to add a state machine by adding
a masquerading (many2one NAT) stage  8-/

-- 
MfG/best regards, helmut springer
                                            [EMAIL PROTECTED]
        
                   "Freedom's just another word for nothing left to lose"
-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]

Reply via email to