• Franco Fichtner's avatar
    firewall: npt alignment · 39eed8a1
    Franco Fichtner authored
    NPT is a kind of abandoned feature that had a custom kernel patch.
    I tried to trace the origin through OpenBSD, but their pf(4) since
    switched away from separate binat rules in the last known form like
    it is still in FreeBSD.
    
    Furthermore, the original GUI commit looks odd in that it tries to
    push the same traffic downwards that would match in the former line,
    which acutally points upwards.  It's either that or completely zapping
    the line.  For now, repair the rules reload by trying to retain the
    spirit of what it tries to achieve and wait for further feedback.
    
    This late bug report also suggests that virtually nobody uses NPT
    today since we've had no upstream reports since at least 15.7 was
    out.
    
    PR: https://forum.opnsense.org/index.php?topic=3076.0
    39eed8a1
filter.inc 146 KB