That Compatibility Thing
- ipfwadm.o and ipchains.o are now modules on top of netfilter.
- Simply insmod to get 2.0 or 2.2-style filtering, including masquerading and redirect!
- Can't currently set masquerading timeouts (shouldn't need to anyway).
- You're not stopped from binding to masquerading ports.
- 2.0-style accounting doesn't get all packets even if interface in promisc. mode