In some email I received from ming fu, sie wrote:
...
> Darren:
>
> Can we take out the line (np->in_flags && !(nflags & np->in_flags)))? It
> only test, in the case of TCP/UDP, whether the incoming packet is TCP or
> UDP. This condition is already tested by line above it which compares
> protocol ID.
Does this patch work ? It makes the two "maskloop" checks the same.
Darren
Index: ip_nat.c
===================================================================
RCS file: /devel/CVS/IP-Filter/ip_nat.c,v
retrieving revision 2.37.2.83
diff -c -r2.37.2.83 ip_nat.c
*** ip_nat.c 2004/07/11 16:41:21 2.37.2.83
--- ip_nat.c 2004/08/07 10:53:04
***************
*** 2611,2618 ****
hv = NAT_HASH_FN(iph, 0, ipf_rdrrules_sz);
for (np = rdr_rules[hv]; np; np = np->in_rnext) {
if ((np->in_ifp && (np->in_ifp != ifp)) ||
! (np->in_p && (np->in_p != fin->fin_p)) ||
! (np->in_flags && !(nflags & np->in_flags)))
continue;
if (np->in_flags & IPN_FILTER) {
if (!nat_match(fin, np, ip))
--- 2610,2619 ----
hv = NAT_HASH_FN(iph, 0, ipf_rdrrules_sz);
for (np = rdr_rules[hv]; np; np = np->in_rnext) {
if ((np->in_ifp && (np->in_ifp != ifp)) ||
! (np->in_p && (np->in_p != fin->fin_p)))
! continue;
! if ((np->in_flags & IPN_RF) &&
! !(nflags & np->in_flags)))
continue;
if (np->in_flags & IPN_FILTER) {
if (!nat_match(fin, np, ip))