In some email I received from Ryan Beasley, sie wrote:
> From a, erm, "policy" perspective, is there any reason I should
> avoid using the fr_{st,nat}putent routines from a transparent proxy?
> I've modified 4.0a source to perform some add'l basic checks
> (incrementing the wildcard counter, associating entries w/ timeout
> queues, etc.) on the incoming entries before insertion and am running
> without problems so far. Doing it this way just seems much nicer
> than inserting "keep state" and IP NAT rules.
>
> Anyone have any ideas / suggestions?
Couple of pointers...
The routines that implement the "put" ioctl expect to be copying data
from userspace, so you'll need to account for that.
Otherwise, I can't see why not.
Darren