diff options
author | Phil Davis <phil.davis@inf.org> | 2015-03-14 20:24:25 +0545 |
---|---|---|
committer | Renato Botelho <garga@FreeBSD.org> | 2015-03-16 08:21:41 -0300 |
commit | 08b02994b1204a48f9283d2b431d32472ce51da5 (patch) | |
tree | 6564b0120323117740d7171191a3260789b0d385 /etc/bogons | |
parent | 06144727b0d97a73b0288d2efb620df9a1d51554 (diff) | |
download | pfsense-08b02994b1204a48f9283d2b431d32472ce51da5.zip pfsense-08b02994b1204a48f9283d2b431d32472ce51da5.tar.gz |
Use subnet address in OPT net rules
Example: LAN IP 10.0.1.1/24 OPT1 IP 10.0.2.1/24
Rules with SRC or DST LANnet correctly have 10.0.0.0/24 (the subnet base address) in /tmp/rules.debug
Rules with SRC or DST OPT1net have 10.0.2.1/24 (the OPT1 IP address with OPT1 net mask) in /tmp/rules.debug
It still works (I think) because actually 10.0.2.1/24 and 10.0.2.0/24 interpreted as a subnet still describes the same set of IP addresses, but it looks odd, as reported by: https://forum.pfsense.org/index.php?topic=90096.msg498474#msg498474
Same issue with IPv6 for OPT1net rules.
This fixes the rule generation to that OPT1net uses the base subnet address in the rule, in the same way that LANnet and WANnet does.
Diffstat (limited to 'etc/bogons')
0 files changed, 0 insertions, 0 deletions