Re: Routing multiple IPv4 blocks

2023-07-29 Thread Peter N. M. Hansteen
On Fri, Jul 28, 2023 at 10:09:31PM +0100, Polarian wrote: > I do have one question, if anyone is willing to answer it, so I have on and > off specified "keep state" depending on when I wrote the rule, but the > following specifies it is the default: > https://www.openbsd.org/faq/pf/filter.html > >

Re: Routing multiple IPv4 blocks

2023-07-27 Thread Zack Newman
On 7/25/23 16:55, Polarian wrote: Also, I didn't choose OpenBSD cause it was easy, I choose it for security, if I slapped OpenWrt I could be done in seconds, but I want to learn and I want to use OpenBSD for security, even at the hit of performance, so I don't care about the complexity, only to k

Re: Routing multiple IPv4 blocks

2023-07-25 Thread Stuart Henderson
>> It can be done, but 1) it means that it's possible for hosts on RFC1918 >> addresses to reach the routable addresses directly without going via the >> router and vice-versa (which may or may not be a problem), 2) you'll >> need to think about how you want to arrange things if you use DHCP, and >

Re: Routing multiple IPv4 blocks

2023-07-25 Thread Stuart Henderson
On 2023-07-25, Zack Newman wrote: > On 7/25/23 06:03, Stuart Henderson wrote: >> 217.169.18.56 is a network address (mask it out against the netmask, >> the remaining "host bits" are all zeroes), you cannot use this (or the >> broadcast address) as a host address > > I am sure you were not trying

Re: Routing multiple IPv4 blocks

2023-07-25 Thread Zack Newman
An individual was kind enough to reach out and inform me that they believe I should have not said "I am sure you were not trying to be 'technical'..." but instead "I am sure you were trying not to be 'technical'..." as the former sounded like I was suggesting Stuart was giving bad advice by being

Re: Routing multiple IPv4 blocks

2023-07-25 Thread Zack Newman
On 7/25/23 06:03, Stuart Henderson wrote: 217.169.18.56 is a network address (mask it out against the netmask, the remaining "host bits" are all zeroes), you cannot use this (or the broadcast address) as a host address I am sure you were not trying to be "technical"; but for people that don't a