Re: Bug#150467: user-defined chains vs. iptables module names

2002-06-21 Thread Patrick Schaaf
> The built-in chain and target names are all fully capitalized. > What about the simple restriction that user-defined chain name cannot be a > string consisting of capitalized letters only. This is again breaking backwards compatibility. For example, most of my rulesets contain two chains, named

Re: Bug#150467: user-defined chains vs. iptables module names

2002-06-21 Thread Jozsef Kadlecsik
On Thu, 20 Jun 2002, Laurence J. Lane wrote: > The problem deals with user-defined chain names clashing with iptables > module names. Basically, it's entirely possible to create a user-defined > chain with the same name (case sensitive) as a target module, but the > new chain cannot be used as a

Re: Bug#150467: user-defined chains vs. iptables module names

2002-06-21 Thread Jozsef Kadlecsik
On Fri, 21 Jun 2002, Patrick Schaaf wrote: > > The built-in chain and target names are all fully capitalized. > > What about the simple restriction that user-defined chain name cannot be a > > string consisting of capitalized letters only. > > This is again breaking backwards compatibility. For e

Re: Bug#150467: user-defined chains vs. iptables module names

2002-06-21 Thread Patrick Schaaf
> What about simply returning by an error code if there is an attempt to > create a chain wich clashes with a target name? Wasn't there recent discussion about "how do I find all available target names"? But I agree in principle, that would be the least intrusive shorttime "rationalization" of th

Re: Bug#150467: user-defined chains vs. iptables module names

2002-06-21 Thread Jozsef Kadlecsik
On Fri, 21 Jun 2002, Patrick Schaaf wrote: > > What about simply returning by an error code if there is an attempt to > > create a chain wich clashes with a target name? > > Wasn't there recent discussion about "how do I find all available > target names"? But I agree in principle, that would be

Re: [PATCH] ROUTE target : bug fixes

2002-06-21 Thread Harald Welte
On Thu, Jun 20, 2002 at 04:12:41PM +0200, Cédric de Launois wrote: > Hi, > > Here is a patch for 'ROUTE' target : thanks. I'd love to apply your patch, but since you have not attached but inlined it, your mail program has wrapped the lines and thus corrupted the patch. Please resend it. Pleas

Re: ipt_recent-0.2.1 [PATCH]

2002-06-21 Thread Harald Welte
On Tue, Jun 18, 2002 at 12:34:39AM -0400, Stephen Frost wrote: > Hey all, > > Version 0.2.1 of my ipt_recent module has been up and running on my thanks. For future reference: please send patches as mime attachment, uncompressed. this way i can read them in the mailer and don't need to save, u

Re: [PATCH] DSCP match/target patches

2002-06-21 Thread Harald Welte
On Mon, Jun 17, 2002 at 06:50:32PM +0100, Iain Barnes wrote: > Harald > > The only thing missing is the Makefile modifications. My knowledge of > the fine art of Makefile writing is sorely lacking, so any help on that > front, from anybody, would be greatly appreciated. I've now managed to solve

performance issues (nat / conntrack)

2002-06-21 Thread Don Cohen
> I'm doing some tcp benches on a netfilter enabled box and noticed > huge and surprising perf decrease when loading iptable_nat module. Rather similar to the results I posted about a week ago. > - Another (old) question: why are conntrack or nat active when there are > no rules configured (

Re: MIME Patches (was [PATCH] ROUTE target : bug fixes)

2002-06-21 Thread Ben Reser
On Fri, Jun 21, 2002 at 07:15:26PM +0200, Harald Welte wrote: > Please try to send patches as mime attachment to ensure no corruption > occurs. Okay this is confusing. Your scoreboard guidelines (http://www.netfilter.org/scoreboard/) say that you should include patches "straight in the body of

[PATCH] ipt_recent-0.2.2

2002-06-21 Thread Stephen Frost
* Harald Welte ([EMAIL PROTECTED]) wrote: > On Tue, Jun 18, 2002 at 12:34:39AM -0400, Stephen Frost wrote: > > Hey all, > > > > Version 0.2.1 of my ipt_recent module has been up and running on my > > thanks. For future reference: please send patches as mime attachment, > uncompressed. this way

About a patch to unclean module.

2002-06-21 Thread Maciej Soltysiak
Hello, I may say now, that I have finished writing the module, updating the lipipt_unclean.c, I have created the patches to the netfilter tree. But, suppose, Harald applies the patch. It will change libipt_unclean.c in a way, that withougt running patch-o-matic it will not compile, because it us

Re: [ANNOUNCE] netfilter/iptables Anonymous CVS has been moved

2002-06-21 Thread Stephen Frost
* Harald Welte ([EMAIL PROTECTED]) wrote: > The anonymous CVS repository for the netfilter/iptables project has been > moved. Harald, Is there anything we need to do to get back on the netfilter cvs-commits list? I havn't seen any commits since the 18th so I'm guessing either we have to s

MSN v/s Iptables !

2002-06-21 Thread Rajeev Jain
Title: MSN v/s Iptables ! Hi, I read some document about allowing MSN voice using Iptables and setup the following commented ruleset in my firewall rules startup file. I did it manually too but didn't help. Could you please take a look at the ruleset below and advice me the correct order OR