Re: Layer 7 application blocking via tc/iptables?

Linux Advanced Routing and Traffic Control

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



 : >  You can place the fwmark on one machine, and then
 : > iptables block it on another if necessary.
 :
 : Can you do that?

No.

 : AFAIK, the fwmark disappears when it leaves the machine.

This is accurate.  The fwmark is metadata and is only available on the box
where the packet has been marked.

-Martin

-- 
Martin A. Brown --- SecurePipe, Inc. --- mabrown@xxxxxxxxxxxxxx

_______________________________________________
LARTC mailing list / LARTC@xxxxxxxxxxxxxxx
http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/

[Index of Archives]     [LARTC Home Page]     [Netfilter]     [Netfilter Development]     [Network Development]     [Bugtraq]     [GCC Help]     [Yosemite News]     [Linux Kernel]     [Fedora Users]
  Powered by Linux