nftables 1.0.8 showing invalid type for ip dscp

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



The following ruleset setting ct mark from ip dscp does not display
the right-hand expression 'ip dscp' correctly when listing the
ruleset.
It instead displays '@nh,8,8 & 0xfc [invalid type]'.  'ip6 dscp' looks normal.

table inet x {
        chain y {
                type filter hook postrouting priority mangle + 1; policy accept;
                ct mark set ip dscp | 0x40 counter
                ct mark set ip6 dscp | 0x40 counter
        }
}

# nft list table inet x
table inet x {
        chain y {
                type filter hook postrouting priority mangle + 1; policy accept;
                meta nfproto ipv4 ct mark set @nh,8,8 & 0xfc [invalid
type] | 0x40 counter packets 3584 bytes 575402
                ct mark set ip6 dscp | 0x40 counter packets 755 bytes 255731
        }
}



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux