ip6tables: --state INVALID matches echo-replies

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Dear list,

I tried to find an answer to this on the web, but I couldn't. Thus
I am turning to you.

On an IPv6 host,

  -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
  -A INPUT -m state --state INVALID -j DROP
  -A INPUT -m state --state NEW -j in-new
  -A in-new -p icmpv6 -icmpv6-type echo-request -j ACCEPT

causes echo-reply to be dropped by the second rule. It works for
IPv4. Is this a bug, or am I doing something wrong?

Thanks,

-- 
martin | http://madduck.net/ | http://two.sentenc.es/
 
"sometimes the urge to do bad is nearly overpowering"
                                                          -- ben horne
 
spamtraps: madduck.bogus@xxxxxxxxxxx

Attachment: digital_signature_gpg.asc
Description: Digital signature (see http://martin-krafft.net/gpg/)


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux