[sclug] Re: Firewalls
J. Mann
jon at spinis-associates.co.uk
Sat Oct 25 09:05:32 UTC 2003
> Apparently, it's planned that the NAT helper stuff in the kernel is
> going to be moved to userland, so more correct (i.e. complex) handling of
> protocols like FTP will be possible. ;-]
Of course, I believe you are correct, and this
is a nice development. However, let us not forget:
NAT is a hack. It is a dirty solution to a
non trivial problem (lack of ip address space).
The correct solution is to implement a fully
routable internet, ala ipv6.
Jon.
More information about the Sclug
mailing list