Re: [Iptables PATCH] extensions: Rename 'flow table' keyword to meter

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sat, Jan 27, 2018 at 12:11:16AM +0530, shyam saini wrote:
> After nft v0.8.1 "flow table" is renamed as meter.
> This should reflect in iptables to nftables translation.
> 
> Before this patch:
> $ iptables-translate -A INPUT -m tcp -p tcp --dport 80 -m hashlimit
> --hashlimit-above 200/sec --hashlimit-mode srcip,dstport
> --hashlimit-name http1 -j DROP
> 
> nft add rule ip filter INPUT tcp dport 80 flow table http1 { tcp dport .
> ip saddr limit rate over 200/second } counter drop
> 
> After this patch:
> $ iptables-translate -A INPUT -m tcp -p tcp --dport 80 -m hashlimit
> --hashlimit-upto 200 --hashlimit-mode srcip --hashlimit-name http3
> --hashlimit-srcmask 24 -j DROP
> 
> nft add rule ip filter INPUT tcp dport 80 meter http3 { ip saddr and
> 255.255.255.0 limit rate 200/second } counter drop

Applied, thanks Shyam.
--
To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html



[Index of Archives]     [Netfitler Users]     [LARTC]     [Bugtraq]     [Yosemite Forum]

  Powered by Linux