On Sat, Mar 21, 2015 at 06:45:09PM +0000, Patrick McHardy wrote: > On 21.03, Pablo Neira Ayuso wrote: > > ip6tables extensions check for this flag to restrict match/target to a > > given protocol. Without this flag set, SYNPROXY6 returns an error. > > That looks like the correct solution to me, thanks! > > I guess we should also fix all the ip6_tables extensions that think > they're matching on the L4 protocol but are actually not enforcing > this. I'll send a follow up patch to fix this. Thanks for reviewing! -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html