Writing nftables extension / modifying packets via nftables and netfilter

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hello!

I would like to write a netfilter module to modify packets going in
and out of my machine (TCP/IP headers, maybe content) after some
analysis of the packet. For this, I wanted to extend nftables with new
matches or targets that control this modification behavior. I've
looked around some, but couldn't find documentation on how to do this
properly using nftables, can someone point me in the right direction?

Using a netfilter/iptables combo, this kind of extension seems to be
pretty well documented (e.g. at the HOWTO page for netfilter hacking
[1]). I could also go this route, but as nftables seems to be poised
to succeed iptables, I wanted to try my hands at using the
future-proof technology.

Regards,

Stephan

[1] http://www.netfilter.org/documentation/HOWTO/netfilter-hacking-HOWTO-4.html

PS: Offtopic: The header of the mailing lists webpage:
http://netfilter.org/mailinglists.html seems to be missing a 't' :
Mailinglists of _he netfilter/iptables project
--
To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html



[Index of Archives]     [Netfitler Users]     [LARTC]     [Bugtraq]     [Yosemite Forum]

  Powered by Linux