On 2021/02/08 11:32, Florian Westphal wrote:
- reject statementShould work in recent kernels.
>
... >> - packet mark Will be present for loopback and it can be set/assigned.
> > ...
conntrack info may be present for loopback case.
> ...
access to l4 header will not work for subsequent fragments.
Thanks, Florian! The above is very good to know while working on my rulesets.
Best regards, Frank