Update HTML documentation from man pages
Some checks failed
C/C++ CI Linux / ${{ matrix.target }} (ubuntu-24.04-arm) (push) Waiting to run
C/C++ CI Linux / ${{ matrix.target }} (ubuntu-latest) (push) Waiting to run
C/C++ CI MacOS / ${{ matrix.target }} (macos-15) (push) Waiting to run
C/C++ CI Windows / ${{ matrix.target }} (windows-2022) (push) Waiting to run
C/C++ CI cmake / ${{ matrix.target }} (macos-15) (push) Waiting to run
C/C++ CI cmake / ${{ matrix.target }} (ubuntu-24.04-arm) (push) Waiting to run
C/C++ CI cmake / ${{ matrix.target }} (ubuntu-latest) (push) Waiting to run
C/C++ CI cmake / ${{ matrix.target }} (windows-2022) (push) Waiting to run
C/C++ CI cmake / ubuntu-latest (wolfSSL) (push) Waiting to run
Update HTML documentation / docs (push) Has been cancelled
Update wiki / wiki (push) Has been cancelled

This commit is contained in:
github-actions[bot] 2026-09-30 16:05:27 +00:00
parent 6f02ec2747
commit ffa1a05009

View File

@ -897,13 +897,18 @@ argument, with 0.0.0.0 as the address, for example <b>parent
be asked to pick the port itself (Linux
<b>IP_LOCAL_PORT_RANGE</b>) it does, otherwise a port is
picked at random from the range and retried if it is already
in use, up to ten times. On Linux the range has to lie
within <i>net.ipv4.ip_local_port_range</i>, commonly
32768-60999: the kernel ignores a range outside it and picks
an ordinary ephemeral port instead. If no port in the range
can be bound, an ephemeral port is used rather than failing
the connection. It can be chained with another parent type,
and the access rule it belongs to decides which requests it
in use, up to ten times. A port which binds but whose pair
with the destination is still closing from an earlier
connection, which Windows refuses at the connect, is retried
in the same way and out of the same ten tries, so a repeated
connection to one destination does not fail for a port it
has just used. On Linux the range has to lie within
<i>net.ipv4.ip_local_port_range</i>, commonly 32768-60999:
the kernel ignores a range outside it and picks an ordinary
ephemeral port instead. If no port in the range can be
bound, an ephemeral port is used rather than failing the
connection. It can be chained with another parent type, and
the access rule it belongs to decides which requests it
applies to, so <b>allow * * * * UDPASSOC</b> followed by
<b>parent 1000 extport 0.0.0.0 40000-40100</b> limits it to
UDP associations. The range is applied when the outgoing