[ previous ] [ next ] [ threads ]
 From:  Manuel Kasper <mk at neon1 dot net>
 To:  =?ISO-8859-1?Q?G=FCnther_Starnberger?= <Guenther dot Starnberger at cs dot or dot at>
 Cc:  m0n0wall dash dev at lists dot m0n0 dot ch
 Subject:  Re: [m0n0wall-dev] keep state and ICMP redirects
 Date:  Mon, 12 Jul 2004 00:04:08 +0200
On 11.07.2004 23:02 +0200, Günther Starnberger wrote:

>  Are there any plans on adding some kind of "ignore state" checkbox
> to the firewall rules? Are there any objections on including this
> in the official version - if not i can code it if I find some time
> in the next week.
>  Another solution for this problem would be to automatically skip
> the "keep state" option if there is a static route to the network
> used in the firewall rule with a gateway in the network to which
> the firewall rule applies.

I think I'll just change the filter rule generator to unconditionally
allow traffic between an interface's main subnet and the statically
routed subnets defined for that same interface. Don't want another
mostly useless and potentially very dangerous option that most users
probably wouldn't be able to understand.

- Manuel