From mboxrd@z Thu Jan 1 00:00:00 1970 From: Pablo Neira Ayuso Subject: Re: ip_conntrack_tuple and marks Date: Sun, 24 Sep 2006 05:14:00 +0200 Message-ID: <4515F7F8.9030000@netfilter.org> References: <451448A9.6000407@gmx.net> Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Cc: Netfilter Development Mailinglist Return-path: To: Carl-Daniel Hailfinger In-Reply-To: <451448A9.6000407@gmx.net> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: netfilter-devel-bounces@lists.netfilter.org Errors-To: netfilter-devel-bounces@lists.netfilter.org List-Id: netfilter-devel.vger.kernel.org Carl-Daniel Hailfinger wrote: > Hi, > > is it possible to add a nfmark field to ip_conntrack_tuple > so that only packets with a certain mark set are matched to > a connection? I'm trying to filter/nat multiple independent > connections with same ip/proto/port tuples on both sides > and the only distinguishing property of the different > connections is their nfmark. Using NOTRACK doesn't help > because it can only exclude packets from tracking, not > match packets to different expectations. Could the connmark match/target be what you need? -- The dawn of the fourth age of Linux firewalling is coming; a time of great struggle and heroic deeds -- J.Kadlecsik got inspired by J.Morris