cyx wrote:
So there is no APIs we can use to manipulate the kernel's iptables, except invoking the "iptables" command from shell? so wired, it should be have some APIs to do the same as the "iptables" does.
Unfortunately not, at least not for C. There is a perl-API, but I forgot its name. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html