On Mon, Mar 11, 2002 at 12:37:40PM -0600, Matthew G. Marsh wrote:
> 
> Attached is the update for FTOS to Iptables 1.2.5 along with some minor
> patches and the inclusion of the GPL module stuff.
> 
> Patch is against the iptables-1.2.5 directory and so includes the
> extensions/.FTOS-test file as well as the changes to the pom/base/ftos.xxx
> parts.

Thanks, I have applied your patch just before releasing 1.2.6.

However, as you might have noticed, there is now an upcoming DSCP and
ECN target.

This means, people will now be able to set the DSCP bits without
intefering with ECN.

I think we should remove the ftos.patch with the next iptables release,
because people will have the following options:

1) use the TOS target for setting all valid TOS values
   without interfering with ECN
2) use the DSCP target for setting all valid DSCP codepoint values
   without interfering with ECN

The FTOS target is potentially harmful to ECN and makes it easy to
violate both old and new usage of the TOS field.

Please feel free to tell me if I've missed something.

> Matthew G. Marsh, President

-- 
Live long and prosper
- Harald Welte / [EMAIL PROTECTED]               http://www.gnumonks.org/
============================================================================
GCS/E/IT d- s-: a-- C+++ UL++++$ P+++ L++++$ E--- W- N++ o? K- w--- O- M+ 
V-- PS++ PE-- Y++ PGP++ t+ 5-- !X !R tv-- b+++ !DI !D G+ e* h--- r++ y+(*)

Reply via email to