Re: [RFD] iptables: mangle table obsoletes filter table

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Patrick McHardy
Date: Thursday, October 11, 2007 - 9:35 pm

Please send mails discussing netfilter to netfilter-devel.

Al Boldi wrote:

There are some minor differences in ordering (mangle comes before
DNAT, filter afterwards), but for most rulesets thats completely
irrelevant. The only difference that really matters is that mangle
performs rerouting in LOCAL_OUT for packets that had their routing
key changed, so its really a superset of the filter table. If you
want to use REJECT in the mangle table, you just need to remove the
restriction to filter, it works fine. I would prefer to also remove
the restriction of MARK, CONNMARK etc. to mangle, they're used for
more than just routing today so that restriction also doesn't make
much sense. Patches for this are welcome.


That would probably confuse people. Just don't use it if you don't
need to.
-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [RFD] iptables: mangle table obsoletes filter table, Patrick McHardy, (Thu Oct 11, 9:35 pm)
Re: [RFD] iptables: mangle table obsoletes filter table, Jan Engelhardt, (Fri Oct 12, 6:01 am)
Re: [RFD] iptables: mangle table obsoletes filter table, Jan Engelhardt, (Fri Oct 12, 6:39 am)
Re: [RFD] iptables: mangle table obsoletes filter table, Patrick McHardy, (Fri Oct 12, 6:48 am)
Re: [RFD] iptables: mangle table obsoletes filter table, Jan Engelhardt, (Fri Oct 12, 7:02 am)
Re: [RFD] iptables: mangle table obsoletes filter table, Patrick McHardy, (Fri Oct 12, 7:03 am)
Re: [RFD] iptables: mangle table obsoletes filter table, Patrick McHardy, (Fri Oct 12, 4:02 pm)
Re: [RFD] iptables: mangle table obsoletes filter table, Bill Davidsen, (Wed Oct 17, 3:37 pm)
Re: [RFD] iptables: mangle table obsoletes filter table, Bill Davidsen, (Wed Oct 17, 4:24 pm)
Re: [RFD] iptables: mangle table obsoletes filter table, Valdis.Kletnieks, (Fri Oct 19, 9:47 pm)
Re: [RFD] iptables: mangle table obsoletes filter table, Jan Engelhardt, (Sat Oct 20, 4:10 am)
Re: [RFD] iptables: mangle table obsoletes filter table, Valdis.Kletnieks, (Sat Oct 20, 9:53 pm)
Re: [RFD] iptables: mangle table obsoletes filter table, Bill Davidsen, (Tue Oct 23, 3:27 pm)