1997-02-09 22:50:16 +00:00
|
|
|
* use fr_tcpstate() with NAT code for increased NAT usage security or even
|
1997-05-25 15:45:04 +00:00
|
|
|
fr_checkstate() - suspect this is not possible.
|
1997-02-09 22:50:16 +00:00
|
|
|
|
|
|
|
* see if the Solaris2 and dynamic plumb/unplumb problem is solvable
|
1997-11-16 04:52:19 +00:00
|
|
|
done ?
|
1997-02-09 22:50:16 +00:00
|
|
|
|
|
|
|
time permitting:
|
|
|
|
|
|
|
|
* load balancing across interfaces
|
|
|
|
|
|
|
|
* record buffering for TCP/UDP
|
|
|
|
|
|
|
|
* modular application proxying
|
1997-05-25 15:45:04 +00:00
|
|
|
on the way
|
1997-02-09 22:50:16 +00:00
|
|
|
|
1997-11-16 04:52:19 +00:00
|
|
|
* keep fragment information for state entries automatically.
|
|
|
|
done for NAT
|
1997-05-25 15:45:04 +00:00
|
|
|
|
1997-11-16 04:52:19 +00:00
|
|
|
* support traceroute through the firewall
|
|
|
|
(i.e. fix up ICMP errors coming back for NAT)
|
1997-05-25 15:45:04 +00:00
|
|
|
done
|
|
|
|
|
1997-11-16 04:52:19 +00:00
|
|
|
* allow multiple ip addresses in a source route list for ipsend
|
1997-05-25 15:45:04 +00:00
|
|
|
|
1997-11-16 04:52:19 +00:00
|
|
|
* complete Linux port to implement all the IP Filter features
|
1998-03-21 10:04:55 +00:00
|
|
|
return-rst done, to/dup-to/fastroute remain - ip_forward() problems :-(
|
|
|
|
|
|
|
|
* add switches to ipmon for better selective control over which logs are
|
|
|
|
read/not read
|
|
|
|
done
|
|
|
|
|
|
|
|
* add a flag to automate src spoofing
|
|
|
|
|
|
|
|
* ipfsync() should change IP#'s in current mappings as well as what's
|
|
|
|
in rules.
|
|
|
|
|
1998-06-20 18:29:38 +00:00
|
|
|
document bimap
|
|
|
|
|
|
|
|
document NAT rule order processing
|
|
|
|
|
|
|
|
add more docs
|