Re: Proposal to apply mask to IP address set on rule

Greg Troxel <[email protected]> Sat, 24 May 2025 15:06:55 -0400
Newsgroups gmane.os.netbsd.devel.network
Message-ID <[email protected]>
Robert Swindells <[email protected]> writes:

> Greg Troxel <[email protected]> wrote:
>> When you are trying to block a neighborhod around an offender, you are
>> just guessing at the subnet size that is likely under the same
>> administrative control.
>
> Isn't the whois record for the address expected to have the correct
> subnet size?
>
> That is what I have always used when adding an entry to a npf blocklist.

Maybe, but it seems there are hosting companies and then somebody gets a
/24.  I have become less concerned about collateral damage over time.
If you've found that there are whois records for small subnets delegated
to customers of a hosting company, that's interesting.

(How one comes up with the mask is orthogonal to the ok/warning/error
discussion.)