-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Mantiene un tracking de las conexiones.
Fijate en esto: Stateful filter and NAT Currently, stateful filtering and NAT is implemented. The ruleset is identical to IPF, minus some options that are not yet implemented (keep frags, return-icmp, etc.). A state basically consists of three address/port pairs. One for the external host, one for the gateway and one for the internal machine that is being NATed (in case it is a NATed connection, otherwise two pairs are identical). Each stateful connection creates a state, and its address is inserted into two trees and one linked list. One tree is sorted on external and gateway address/port, the other on external and internal address/port. The entries in each tree are unique (no duplicate keys). When a packet comes in on the (external) interface, the external-gateway tree is searched. When a packet goes out, the external-internal tree is searched. NATed connections always have state, and the three address/port pairs are used to translate addresses. There is no other NAT mapping table of any kind. Tree searches (the primary operation which occurs for every packet) are O(log n), inserts and removals as well (they occur only once for each connection). The linked list is used to traverse all states when expired states are purged. This is a O(n) operation, but occurs at most once every 10 seconds (not for every packet). A sorted container doesn't make sense: the expire time of a state (the key) usually changes with each packet. The design handles large numbers states (concurrent connections) decently. Right now, the memory usage for the states is the limit. There is much to be optimized (whole bytes are wasted to hold bits, etc.). El Tuesday 20 November 2001 14:05, Pablo Crembil escribi�: > Yo lo habia leido como SPM, en unos Firewalls Lucent. Vos a que te referis > con el concepto de Statefull Filter?. > > Tnx. Seba. y Saludos. > - - - - - - - - - - - - - > Pablo Crembil - Technology Team - Openware Argentina > Vis�tenos en http://www.openware.com.ar > > > > Sebasti�n D. > Criado Para: [EMAIL PROTECTED] > <scriado@ciuda cc: > d.com.ar> Asunto: Re: [LUG.ro] SPM > Enviado por: > owner-lugro@lu > gro.org.ar > > > 20/11/01 01:55 > PM > Por favor, > responda a > lugro > > > > > > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > �A que te referis? �A Statefull Filter? > > Si es as�, si lo soporta. > > Saludos. > > El Tuesday 20 November 2001 10:44, Pablo Crembil escribi�: > > Gente, > > saben por casualidad si IPTables soporta Statefull Package Managment > > ? > > > Saludos. > > - - - - - - - - - - - - - > > Pablo Crembil - Technology Team - Openware Argentina > > Vis�tenos en http://www.openware.com.ar > > - -- > - -- > Sebasti�n D. Criado - [EMAIL PROTECTED] > L.U.G.R.o - http://www.lugro.org.ar > Linux Registered User # 146768 > - ------------------------------------------------------------------- > "Si el Universo fuera un programa estar�a hecho en C, y correr�a sobre > un sistema UNIX" > An�nimo. > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.0.6 (GNU/Linux) > Comment: For info see http://www.gnupg.org > > iD8DBQE7+oP38hmHQ8ZCg0IRAmcuAJ9VY0H9FnYCpK0NNuvKCwytKHAu0gCfWm+n > 5zuwu9pQCzbfMyROMwVbsyA= > =9Pqg > -----END PGP SIGNATURE----- - -- - -- Sebasti�n D. Criado - [EMAIL PROTECTED] L.U.G.R.o - http://www.lugro.org.ar Linux Registered User # 146768 - ------------------------------------------------------------------- "Si el Universo fuera un programa estar�a hecho en C, y correr�a sobre un sistema UNIX" An�nimo. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info see http://www.gnupg.org iD8DBQE7+swW8hmHQ8ZCg0IRAnOKAKDMJKkmtjfgpydjAQWC9Jea7rbygACfbHae s5ep3AuJsWv4OM75FNWUGfg= =W52l -----END PGP SIGNATURE-----
