Down with the mangle table! :-)

Brad Chapman kakadu@earthlink.net
Sun, 08 Jul 2001 18:40:13 -0400


Mr. Kadlecsik,

   I can't quite figure out exactly what it is you mean. If I'm wrong,
sorry in advance ;-)

   Are you talking about a userspace-based iptable registration system
where you can have iptables with built-in chains without patching the
kernel? Something like X where you load .so files like kernel modules
and access the table using either current iptables or a newer program?

   If you are, good! That sounds cool, but looks like a 2.5 thing
and also might be somewhat slow.

Comments, sir?

Brad

Jozsef Kadlecsik wrote:

> Hello,
> 
> Just a crazy idea: what's your opinion on user tables instead of
> mangle(/prestate, etc) tables? A user table could be registered at any
> hook(s) at any unused priority. Thus if someone does not need the mangle
> functionality at all hooks, he/she could create just the appropriate
> table. Playing with the priorities, it could add even more flexibility to
> the system.
> 
> Overkill?
> 
> Regards,
> Jozsef
> -
> E-mail  : kadlec@blackhole.kfki.hu, kadlec@sunserv.kfki.hu
> WWW-Home: http://www.kfki.hu/~kadlec
> Address : KFKI Research Institute for Particle and Nuclear Physics
>           H-1525 Budapest 114, POB. 49, Hungary
> 
> 
> 
>