Moin,

On Monday 08 June 2009 14:22:32 I wrote:
> [stuff]

If anybody's interested, my current work (including history) is available on 
GitHub [1].  Current state:

* Works on 8.09.1, should work on trunk as well.

* Moved some stuff around.  Only refactoring, not a single firewall rule 
changed (until now).  Except...

* I introduced an iptables wrapper, see files/lib/iptables.sh and [2] to get 
an idea.

* It applies all rules both to iptables and ip6tables, but only if the needed 
table is available.  Ie. no NAT for IPv6 (if not installed), but broken rules 
if IP addresses are used in a rule.

Next step:

* Look at the IP addresses and apply the rules to the correct tables only.

And again:

> > > Any comments, ideas, flames?  I'm also hanging around on #openwrt as
> > > moonflux.

Cheers,
Malte


[1]http://github.com/mss/sixwrt-packages/tree/firewall-hack/package/firewall
[2]http://github.com/mss/sixwrt-
packages/commit/4094d813a1562562761381e05f21d61d09b9dff6


-- 
   
_______________________________________________
openwrt-devel mailing list
openwrt-devel@lists.openwrt.org
https://lists.openwrt.org/mailman/listinfo/openwrt-devel

Reply via email to