All of lore.kernel.org
 help / color / mirror / Atom feed
* Problem with two addrtype matches in one iptables rule.
@ 2005-05-16  6:09 Taylor, Grant
  2005-05-17  1:35 ` Patrick McHardy
  0 siblings, 1 reply; 3+ messages in thread
From: Taylor, Grant @ 2005-05-16  6:09 UTC (permalink / raw)
  To: kaber; +Cc: netfilter

Hi, my name is Grant Taylor.  I'm playing with your addrtype match extension to iptables.  I must say that I like it very much.  However I have a slight problem with it.  Namely I am apparently only able to have one addrtype match in any given rule.  I would like to use two addrtype matches, one for the source address, and one for the destination address in my iptables rules.  Do you know of any limitations to the addrtype match extension that would be causing this?  Below is an example rule of what I am currently using as well as what I would like to be able to do:

# current rule:
iptables -t filter -A INPUT -i eth1 -m pkttype --pkt-type broadcast -m addrtype --src-type broadcast -s 0.0.0.0 -d 255.255.255.255 -p udp --sport 68 --dport 67 -j ACCEPT

# desired rule:
iptables -t filter -A INPUT -i eth1 -m pkttype --pkt-type broadcast -m addrtype --src-type broadcast -m addrtype --dst-type broadcast -s 0.0.0.0 -d 255.255.255.255 -p udp --sport 68 --dport 67 -j ACCEPT

Any comments or suggestions would be greatly appreciated.



Grant. . . .

P.S.  This email was sent to Patrick McHardy (directly) as well as CCed to the NetFilter (general) mailing list.


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2005-05-17  5:48 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-05-16  6:09 Problem with two addrtype matches in one iptables rule Taylor, Grant
2005-05-17  1:35 ` Patrick McHardy
2005-05-17  5:48   ` Taylor, Grant

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.