Re: iptables 1.4.11, cannot invert tcp flags

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Tuesday 2011-06-07 23:22, Olaf wrote:

> On 2011-06-07 16:06, Patrick McHardy wrote:
>
>>> with 1.4.11 I can no longer invert --syn nor it's equivalent --tcp-flags
>>> SYN,RST,ACK,FIN SYN.
>>> Both show up 'normal' (tcp flags:0x17/0x02) instead of 'inverted' (tcp
>>> flags:!0x17/0x02) when listing rules.
>>> Works fine when using 1.4.10 or older versions.
>>
>> It works for me when using "-p tcp -m tcp ! --syn", but not when
>> using "-p tcp ! --syn", so I guess something is broken in command
>> parsing for implicitly loaded matches.
>>
>> CCed Jan, who can probably help.
>
> Sure looks that way :-)

Fixes sent in.
--
To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html


[Index of Archives]     [Netfitler Users]     [LARTC]     [Bugtraq]     [Yosemite Forum]

  Powered by Linux