On Wed, 29 May 2013, Dash Four wrote: > This series of 4 patches implements "inner" flag option in the set > iptables match, allowing matching based on the properties > (source/destination IP address, protocol, port and so on) of the > original (inner) connection in the event of the following > ICMP[v4,v6] messages: > > ICMPv4 destination-unreachable (code 3); > ICMPv4 source-quench (code 4); > ICMPv4 time-exceeded (code 11); > ICMPv6 destination-unreachable (code 1); > ICMPv6 packet-too-big (code 2); > ICMPv6 time-exceeded (code 3); > > > Dash Four (4): > ipset: minor variable-naming corrections > ipset: add "inner" flag implementation > iptables: add set match "inner" flag support > iptables (userspace): add set match "inner" flag support I can review your patches in a few days, a quick look is not enough. Best regards, Jozsef - E-mail : kadlec@xxxxxxxxxxxxxxxxx, kadlecsik.jozsef@xxxxxxxxxxxxx PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt Address : Wigner Research Centre for Physics, Hungarian Academy of Sciences H-1525 Budapest 114, POB. 49, Hungary -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html