Re: Proposal to apply mask to IP address set on rule

Emmanuel Nyarko <[email protected]>
Newsgroups gmane.os.netbsd.devel.network
Message-ID <[email protected]>

> On 21 May 2025, at 10:11 PM, Greg Troxel <[email protected]> wrote:
> 
> Emmanuel Nyarko <[email protected]> writes:
> 
>> I think a simple warning will do. That rightmost bits are not 0s.
> 
> Certainly better than silent failure, but I think one should be able to
> use prefixes like 192.168.1.7/24.  As I said, that is a way of
> documenting that it was .7 that got it added, but that the intent was
> to block the neighborhood.
Very good case here.i couldn’t agree more.

But I think that’s an information you can not easily know sometimes. Or ?
 Especially when dealing with incident responses after you’re suspecting malicious activities from a source ip and maybe trying to block. Might be from a diff network, etc. so should probably warn to use a .0 when adding a mask.

Emmanuel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.