Re: Question on raw table and match state

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Fri, 11 Feb 2011, Pandu Poluan wrote:

> On Fri, Feb 11, 2011 at 14:46, Pandu Poluan <pandu@xxxxxxxxxxx> wrote:
> > I am wondering if the following rule will work:
> >
> > iptables -t raw -A PREROUTING -p icmp -m state --state
> > RELATED,ESTABLISHED -j ACCEPT
> 
> Okay, to answer my own question: It won't work.

Yes, and that's just OK: in the raw table the state of the packets are not 
known yet.

Best regards,
Jozsef
-
E-mail  : kadlec@xxxxxxxxxxxxxxxxx, kadlec@xxxxxxxxxxxx
PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt
Address : KFKI Research Institute for Particle and Nuclear Physics
          H-1525 Budapest 114, POB. 49, Hungary
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux