OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: About pf(4) NAT/BINAT/RDR and adding reflect.

From: Stuart Henderson (stuspacehopper.org)
Date: Sat Mar 01 2008 - 06:03:21 CST


On 2008/03/01 12:10, Ermal Lugi wrote:
> On Sat, Mar 1, 2008 at 11:36 AM, Stuart Henderson <stuspacehopper.org> wrote:
> > On 2008/03/01 11:24, Ermal Lugi wrote:
> > > > | [demime 1.01d removed an attachment of type text/x-patch which had a name of pf_dscp.diff]
> > > >
> > > > And your patch got stripped - please include inline ;)
> > >
> > > Here is the patch:
> >
> > there was me hoping it was going to be something for scrub to
> > set/clear them :-)
> >
> >
> What do you mean?

It would definitely be nice to be able to clear DSCP bits from
untrusted systems. It might also be useful to some people if they
could add/change DSCP from a PF rule (i.e. mark certain traffic
with certain DSCP, based on interface/port/IP address/etc).