--- Begin Message ---
- Subject: iptables dry rules testing
- From: Joris Huver <j.huver@xxxxxxxxxxxxxxxxxx>
- Date: Tue, 08 Mar 2011 15:14:46 +0100
- In-reply-to: <S1755403Ab1CHOHd/20110308140733Z+70@xxxxxxxxxxxxxxx>
- Organization: Networking4all
Hi, i've been searching for a way to test a rule set. Would be nice if it can be done by asking iptables to check how a situation is handled. Without having to generate actual traffic. for instance via a 'check' flag or so. iptables --check "type tcp source 10.163.199.239 dport 22 flag syn/ack" and it returning that rule nr.x,y&z apply to it. Or some other cleverer way.. Is there some way it can be done? Cheers
--- End Message ---