Re: skip other iptables marking if packet is already marked

Linux Advanced Routing and Traffic Control

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



>
> I have many iptables setmark commands, but as soon
> as there is one match, I would like to skip all the rest.
> How to do this.

-- cut --

> Wonder if it will work ?
> My next question is should I use -j ACCEPT or -j RETURN ?

-j RETURN

iptables -t mangle -A <chain> <rule 1> -j MARK --set-mark <mark 1>
iptables -t mangle -A <chain> <rule 1> -j RETURN
iptables -t mangle -A <chain> <rule 2> -j MARK --set-mark <mark 2>
iptables -t mangle -A <chain> <rule 2> -j RETURN
iptables -t mangle -A <chain> <rule 3> -j MARK --set-mark <mark 3>
iptables -t mangle -A <chain> <rule 3> -j RETURN

you must enter two lines with the same rule for each mark.
_______________________________________________
LARTC mailing list / LARTC@xxxxxxxxxxxxxxx
http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/

[Index of Archives]     [LARTC Home Page]     [Netfilter]     [Netfilter Development]     [Network Development]     [Bugtraq]     [GCC Help]     [Yosemite News]     [Linux Kernel]     [Fedora Users]
  Powered by Linux