Re: Proposal to apply mask to IP address set on rule
Greg Troxel <[email protected]> Sat, 24 May 2025 15:06:55 -0400
| Newsgroups | gmane.os.netbsd.devel.network |
|---|---|
| Message-ID | <[email protected]> |
Robert Swindells <[email protected]> writes: > Greg Troxel <[email protected]> wrote: >> When you are trying to block a neighborhod around an offender, you are >> just guessing at the subnet size that is likely under the same >> administrative control. > > Isn't the whois record for the address expected to have the correct > subnet size? > > That is what I have always used when adding an entry to a npf blocklist. Maybe, but it seems there are hosting companies and then somebody gets a /24. I have become less concerned about collateral damage over time. If you've found that there are whois records for small subnets delegated to customers of a hosting company, that's interesting. (How one comes up with the mask is orthogonal to the ok/warning/error discussion.)