| |||
| [Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] |
I can tell you from experience you're going to have a hard time doing things at the IP filter layer. IPFW is kind of hacked in the Mac OS X stack between the interface layer and the IP layer. Therefore it can do things that are not possible at either layer alone.I'm posting my intention to port pf (4) (http://www.freebsd.org/cgi/ man.cgi?query=pf&sektion=4) to an NKE for use as a replacement or complement to the current ipfw2.
My experience comes from trying to write a similar replacement for IPFW. I'm not familiar with PF per-se but I imagine our requirements were pretty close to what PF and IPFW provide.According to the Network Kernel Extensions Programming Guide (http:// developer.apple.com/documentation/Darwin/Conceptual/NKEConceptual/ index.html) it seems I might use an Interface Filter KPI mechanism to accomplish such a task. So I ask those who are more familiar with NKEs, is this a reasonable task, am I sane to try it, and do you have any words of advice?
Ryan
_______________________________________________ Do not post admin requests to the list. They will be ignored. Darwin-dev mailing list (email@hidden) Help/Unsubscribe/Update your Subscription: http://lists.apple.com/mailman/options/darwin-dev/email@hidden
| Home | Archives | FAQ | Terms/Conditions | Contact | RSS | Lists | About |
Visit the Apple Store online or at retail locations.
1-800-MY-APPLE
Contact Apple | Terms of Use | Privacy Policy
Copyright © 2007 Apple Inc. All rights reserved.