Re: Iptables rules with module string give strange counter results

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 11/15/2012 8:28 PM, Vladimir Budnev wrote:
No, its casual server. Iron and ugly:)
src host is ther server ip and the destination comes from browser
loading gentoo.org
Iv posted as simple example as could imagine and which illustrates
situation. To avoid some misconfiguration with postrouting or
prerouting or smth. It is just simple OUTPUT chain of filter table

I would say its understood why it will mark specific packets.
I have never used this module but it seems to me that you need to use some connection tracking\marking to make one match effect the whole connection.

Anyway Gentoo.org is not using index.php but xml...
net-filter it's logging by packets. and this is what a match means to me in the string sense of the *match*.

Regards,
Eliezer

--
Eliezer Croitoru
https://www1.ngtech.co.il
IT consulting for Nonprofit organizations
eliezer <at> ngtech.co.il
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux