[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: Matching rule against IP subnet



Hallvard B Furuseth <h.b.furuseth@usit.uio.no> wrote:

> Remember that even if it were, OpenLDAP does not support indexing for
> such filters.  So each search would have to inspect every IP-subnet
> entry in scope.

Even if indexing is not available, the feature would still be useful for
ACL.

> BTW, one point to keep in mind: What do IP ranges look like in IPv6?

Same look: address "/" prefix
IPv6 addresses contain ":", prefixes are from 0 to 128
IPv4 addresses contain ".", prefixes are from 0 to 32.

-- 
Emmanuel Dreyfus
http://hcpnet.free.fr/pubz
manu@netbsd.org