Re: model, granularity and ranges
Wes Hardaker <[email protected]>
| Newsgroups | gmane.ietf.ipsp |
|---|---|
| Organization | Network Associates - NAI Labs |
| Message-ID | <[email protected]> |
>>>>> On Tue, 14 May 2002 15:38:22 +0200, Eric Vyncke <[email protected]> said: Eric> This is a good point and I would follow your recommendation but Eric> rephrased it like 'when the IPHeadersFilter specifies an IP Eric> address range then the Granularity property cannot be set to 1 Eric> (= subnet). That's fine too. It moves the error checking to configuration time, rather than run time so that makes perfect sense. The problem is that dynamic changes to policy will cause a problem. Consider the case when rules are being modified dynamically and a filter is changed from a singe address to a range. The actions then need to be consulted for all rules which contain the particular filter to ensure they're still appropriate. IE, is the reverse case also true? Can you change a filter to a range if it is currently associated with an action which has a granularity of subnet? (While writing this, I'm realizing there are other problems with granularity being tied to the actions... What happens when multiple IPHeaderFilters are evaluated under a rule and have different narrower and wider filtering properties? Like two filters with different subnet checks that both match the address. What does a "subnet" granularity mean then? Take the wider of the 2?) -- Wes Hardaker NAI Labs Network Associates