From a, erm, "policy" perspective, is there any reason I should
avoid using the fr_{st,nat}putent routines from a transparent proxy?
I've modified 4.0a source to perform some add'l basic checks
(incrementing the wildcard counter, associating entries w/ timeout
queues, etc.) on the incoming entries before insertion and am running
without problems so far.  Doing it this way just seems much nicer
than inserting "keep state" and IP NAT rules.

Anyone have any ideas / suggestions?

-- 
ryan beasley                            <[EMAIL PROTECTED]>
GPG ID: 0x16EFBD48

Attachment: pgp00000.pgp
Description: PGP signature

Reply via email to