Re: Bad doc pointer?
Michael Richardson <[email protected]>
| Newsgroups | gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- >>>>> "Hugh" == Hugh Daniel <[email protected]> writes: Hugh> I also note that there is no RCSID tag in the Hugh> policies/block file. Fixed. Hugh> I also read this: Hugh> # This file defines the set of CIDRs (network/mask-length) to which Hugh> # communication should never be allowed. Hugh> and I guess I can't use FQDN's here? I was not sure quite what was Hugh> not allowed, so I read the doc file referenced (once I found it) and Hugh> found this: You can not use FQDNs. They may no sense here. Hugh> """ Hugh> block Hugh> Block listed IP addresses from communicating with this machine. Hugh> """ Hugh> So maybe the IP address (not CIDR?) can't send packets to me but I Hugh> can send packets to it? To deal with this confusion I used to call Hugh> this policy blockdrop. Yeah, the sense is wrong. The file says the right thing: # This file defines the set of CIDRs (network/mask-length) to which # communication should never be allowed. Hugh> I can't find anything in the man pages on what the default policy Hugh> groups do. Claudia? ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON |net architect[ ] [email protected] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) Comment: Finger me for keys iQCVAwUBPk/3z4qHRg3pndX9AQGjMgQA7XH3zLgYHKM+PqXzoN2A8AWC3CZNgsrf U+lyCOtkOOZ0zhXMhC8GdrhvD9yUGqZZtNe/arrvjs4jMxrFQYWZA5CYFrZVdF9W FSaeDw36owvDUsNDkXCDNtBfpiUEKaH2hsRHE6Yvfl3i48sm+pQmQ1ShonKr5rv4 9cIaZFahtzQ= =Ez3E -----END PGP SIGNATURE-----