Hi Darren,
It worked for me, in my limited case of allowing non-tcp/udp to redirect. However, I don't know if I breaked something else.
The "nflags" and "np->in_flags" does not change within the "maskloop:", so this test is the same within the maskloop:. If you think there is something which might be broken by my change, drop me a line, I can check it out.
If you are concerned of the change I made, we can certainly make it more restrictive. such as:
if ((np->in_ifp && (np->in_ifp != ifp)) ||
(np->in_p && (np->in_p != fin->fin_p))||
(np->in_flags && nflags && (nflags & np->in_flags)))Regards, Ming
Darren Reed wrote:
In some email I received from ming fu, sie wrote:
...
Darren:
Can we take out the line (np->in_flags && !(nflags & np->in_flags)))? It only test, in the case of TCP/UDP, whether the incoming packet is TCP or UDP. This condition is already tested by line above it which compares protocol ID.
Does this patch work ? It makes the two "maskloop" checks the same.
Darren
Index: ip_nat.c
===================================================================
RCS file: /devel/CVS/IP-Filter/ip_nat.c,v
retrieving revision 2.37.2.83
diff -c -r2.37.2.83 ip_nat.c
*** ip_nat.c 2004/07/11 16:41:21 2.37.2.83
--- ip_nat.c 2004/08/07 10:53:04
***************
*** 2611,2618 ****
hv = NAT_HASH_FN(iph, 0, ipf_rdrrules_sz);
for (np = rdr_rules[hv]; np; np = np->in_rnext) {
if ((np->in_ifp && (np->in_ifp != ifp)) ||
! (np->in_p && (np->in_p != fin->fin_p)) ||
! (np->in_flags && !(nflags & np->in_flags)))
continue;
if (np->in_flags & IPN_FILTER) {
if (!nat_match(fin, np, ip))
--- 2610,2619 ----
hv = NAT_HASH_FN(iph, 0, ipf_rdrrules_sz);
for (np = rdr_rules[hv]; np; np = np->in_rnext) {
if ((np->in_ifp && (np->in_ifp != ifp)) ||
! (np->in_p && (np->in_p != fin->fin_p)))
! continue;
! if ((np->in_flags & IPN_RF) &&
! !(nflags & np->in_flags)))
continue;
if (np->in_flags & IPN_FILTER) {
if (!nat_match(fin, np, ip))
