Re: Proposal to apply mask to IP address set on rule
Gert Doering <[email protected]> Sat, 24 May 2025 14:07:03 +0200
| Newsgroups | gmane.os.netbsd.devel.network |
|---|---|
| Message-ID | <[email protected]> |
Hi, On Sat, May 24, 2025 at 01:37:58PM +0200, [email protected] wrote: > Vendor C applies netmasks to the address in ACLs; actually the > configuration read back has the masked address. I guess a high > percentage of networking engineers worldwide are used to that > behaviour... The problem with vendor $C is that it's not "netmasks" but "wildcard bits", so to match a /24 you'd do deny ip 192.168.3.7 0.0.0.255 (rewritten to ".. 192.168.3.0 ..") while the naive deny ip 192.168.3.7 255.255.255.0 would end up in the config as "0.0.0.3 255.255.255.0"... So that's not the best example for "principle of least astonishment" :-) gert -- "If was one thing all people took for granted, was conviction that if you feed honest figures into a computer, honest figures come out. Never doubted it myself till I met a computer with a sense of humor." Robert A. Heinlein, The Moon is a Harsh Mistress Gert Doering - Munich, Germany [email protected]