Re: [FWD: NAT counting]

Harald Welte (laforge@gnumonks.org)
Tue, 11 Feb 2003 12:45:29 +0100


This is a MIME-formatted message. If you see this text it means that your
E-mail software does not support MIME-formatted messages.

--=_courier-21894-1044964222-0001-2
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Tue, Feb 11, 2003 at 08:49:59AM +0100, Leonard Milcin, Jr wrote:
> Luck, Tony wrote:
> > (...)
> > The fact that someone can deduce how many hosts are hidden behind
> > a NAT gateway may, or may not, be a bug ... depending on whether you
> > think that the NAT is supposed to keep this number a secret. But there
> > (...)
>=20
> Sometimes it is desirable to hide the true number of hosts behind the=20
> NAT. For example in home-made Linux NAT Gateways where few people share=
=20
> the same internet connections even if ISP doesn't allow sharing=20
> connection ;)

No doubt. But as I initially stated: I don't want to do this by
default. We will give the user a choice [by means of an IPID target in
the mangle table].

--=20
- Harald Welte <laforge@gnumonks.org> http://www.gnumonks.org/
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D
"If this were a dictatorship, it'd be a heck of a lot easier, just so long
as I'm the dictator." -- George W. Bush Dec 18, 2000

--=_courier-21894-1044964222-0001-2
Content-Type: application/pgp-signature
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE+SOJZXaXGVTD0i/8RAlNmAJwKC6bkE/lbW1Lq7ZzZ9y79kIgQTACfe+Zt
kjGdZP2WgKSq9dR+SH7JR3M=
=Xgyt
-----END PGP SIGNATURE-----

--=_courier-21894-1044964222-0001-2--