Re: missing module for tcp-flags match?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hello,

Henning Sprang a écrit :
Sorry for having posted this message twice. I did't see it coming back
through the list, and realized I sent it from the wrong address.

Messages sent with an address which is not subscribed to the list must wait to be approved by a list manager, this can take some time.

I then sent it again from the address whic is actually subscribed.
Now that I wondered why even the second mail didn't come back to me, I
looked in the list archive and saw that the mail actually came through
the list, even twice. I wonder why I didn't get a copy, because all
other lists I know send copies of mails also to the sender himself -
is the netfilter list different in this?

There is an option to not receive a copy of your own messages, maybe you enabled it.

When tyring to set up the rule:

iptables -A INPUT --protocol tcp --tcp-flags ALL SYN,ACK -j DROP

I only get the error:

iptables: No chain/target/match by that name

When I remove the tcp-flags part, the rules is accepted. I assume to
be missing a kernel module for tcp-flags match, but have no idea which
module this could be. Which Kernel module is required for getting
tcp-flags matches?

AFAIK, there is no specific module for --tcp-flags. It is a standard tcp match, like --dport and --sport. I see no reason why you get an error.



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux