Re: Proposal to apply mask to IP address set on rule

Gert Doering <[email protected]> Sat, 24 May 2025 14:07:03 +0200
Newsgroups gmane.os.netbsd.devel.network
Message-ID <[email protected]>
Hi,

On Sat, May 24, 2025 at 01:37:58PM +0200, [email protected] wrote:
> Vendor C applies netmasks to the address in ACLs; actually the
> configuration read back has the masked address. I guess a high
> percentage of networking engineers worldwide are used to that
> behaviour...

The problem with vendor $C is that it's not "netmasks" but "wildcard
bits", so to match a /24 you'd do

  deny ip 192.168.3.7 0.0.0.255

(rewritten to ".. 192.168.3.0 ..") while the naive

  deny ip 192.168.3.7 255.255.255.0

would end up in the config as "0.0.0.3 255.255.255.0"...

So that's not the best example for "principle of least astonishment" :-)

gert
-- 
"If was one thing all people took for granted, was conviction that if you 
 feed honest figures into a computer, honest figures come out. Never doubted 
 it myself till I met a computer with a sense of humor."
                             Robert A. Heinlein, The Moon is a Harsh Mistress

Gert Doering - Munich, Germany                             [email protected]