Re: model, granularity and ranges

Wes Hardaker <[email protected]>
Newsgroups gmane.ietf.ipsp
Organization Network Associates - NAI Labs
Message-ID <[email protected]>
>>>>> On Tue, 14 May 2002 15:38:22 +0200, Eric Vyncke <[email protected]> said:

Eric> This is a good point and I would follow your recommendation but
Eric> rephrased it like 'when the IPHeadersFilter specifies an IP
Eric> address range then the Granularity property cannot be set to 1
Eric> (= subnet).

That's fine too.  It moves the error checking to configuration time,
rather than run time so that makes perfect sense.

The problem is that dynamic changes to policy will cause a problem.
Consider the case when rules are being modified dynamically and a
filter is changed from a singe address to a range.  The actions then
need to be consulted for all rules which contain the particular filter
to ensure they're still appropriate.  IE, is the reverse case also
true?  Can you change a filter to a range if it is currently
associated with an action which has a granularity of subnet?

(While writing this, I'm realizing there are other problems with
granularity being tied to the actions...  What happens when multiple
IPHeaderFilters are evaluated under a rule and have different narrower
and wider filtering properties?  Like two filters with different
subnet checks that both match the address.  What does a "subnet"
granularity mean then?  Take the wider of the 2?)

-- 
Wes Hardaker
NAI Labs
Network Associates
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.