Re: [PATCH 3/5] netfilter: xtables: inclusion of xt_TEE

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Patrick McHardy
Date: Thursday, April 1, 2010 - 4:54 am

Jan Engelhardt wrote:

That might make it unnessarily complicated to use src-based routing
when using TEE. I guess you'd usually have a host for logging or IDS
somewhere on a private network and TEE packets there. So specifying
oif and gateway seems most useful to me.


Yeah, but currently it does allow packets to be looped back. These
packets will also go through the netfilter hooks again.

--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
nf-next: TEE and nesting, Jan Engelhardt, (Wed Mar 31, 3:38 am)
[PATCH 3/5] netfilter: xtables: inclusion of xt_TEE, Jan Engelhardt, (Wed Mar 31, 3:38 am)
[PATCH 4/5] netfilter: xtables2: make ip_tables reentrant, Jan Engelhardt, (Wed Mar 31, 3:38 am)
Re: [PATCH 3/5] netfilter: xtables: inclusion of xt_TEE, Patrick McHardy, (Thu Apr 1, 3:34 am)
Re: [PATCH 3/5] netfilter: xtables: inclusion of xt_TEE, Jan Engelhardt, (Thu Apr 1, 4:39 am)
Re: [PATCH 3/5] netfilter: xtables: inclusion of xt_TEE, Patrick McHardy, (Thu Apr 1, 4:54 am)