Re: Constraints on nft expressions and statements in inet ingress chains

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 2021/02/08 11:32, Florian Westphal wrote:
- reject statement
Should work in recent kernels.
>
... >> - packet mark
Will be present for loopback and it can be set/assigned.
>
> ...
conntrack info may be present for loopback case.

> ...
access to l4 header will not work for subsequent fragments.

Thanks, Florian! The above is very good to know while working on my rulesets.

Best regards,
Frank




[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux