nft - no equivalency to ipset hash:port:hash for differing sized subnets

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi all,

One feature that I've noticed is missing is that there is no
hash:port:hash equivalent in nftables, which I'm starting to think is
quite a big gap.

Currently the wiki
(https://wiki.nftables.org/wiki-nftables/index.php/Concatenations#Examples)
says that you can do this, however this will only work for one subnet
per set.  So, you cannot have a large set of differently sized
subnets.

So, I'm worried this may have went unnoticed especially since the wiki
thinks you can (however, it's very limited).

Does anyone know if there is any effort going on to remedy this? And
what would be the best way to put in a feature request if it is not
being worked on?

Thank you,
Fran Fitzpatrick
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux