In some email I received from ming fu, sie wrote:
...
> Darren:
> 
> Can we take out the line (np->in_flags && !(nflags & np->in_flags)))? It 
> only test, in the case of TCP/UDP, whether the incoming packet is TCP or 
> UDP. This condition is already tested by line above it which compares 
> protocol ID.

Does this patch work ?  It makes the two "maskloop" checks the same.

Darren

Index: ip_nat.c
===================================================================
RCS file: /devel/CVS/IP-Filter/ip_nat.c,v
retrieving revision 2.37.2.83
diff -c -r2.37.2.83 ip_nat.c
*** ip_nat.c    2004/07/11 16:41:21     2.37.2.83
--- ip_nat.c    2004/08/07 10:53:04
***************
*** 2611,2618 ****
                hv = NAT_HASH_FN(iph, 0, ipf_rdrrules_sz);
                for (np = rdr_rules[hv]; np; np = np->in_rnext) {
                        if ((np->in_ifp && (np->in_ifp != ifp)) ||
!                           (np->in_p && (np->in_p != fin->fin_p)) ||
!                           (np->in_flags && !(nflags & np->in_flags)))
                                continue;
                        if (np->in_flags & IPN_FILTER) {
                                if (!nat_match(fin, np, ip))
--- 2610,2619 ----
                hv = NAT_HASH_FN(iph, 0, ipf_rdrrules_sz);
                for (np = rdr_rules[hv]; np; np = np->in_rnext) {
                        if ((np->in_ifp && (np->in_ifp != ifp)) ||
!                           (np->in_p && (np->in_p != fin->fin_p)))
!                               continue;
!                       if ((np->in_flags & IPN_RF) &&
!                           !(nflags & np->in_flags)))
                                continue;
                        if (np->in_flags & IPN_FILTER) {
                                if (!nat_match(fin, np, ip))

Reply via email to