From: Bart De Schuymer <bdschuym@pandora.be>
To: agashi shipora <gashipo@gmail.com>
Cc: netfilter-devel@vger.kernel.org, netfilter@vger.kernel.org
Subject: Re: uisng L7 filter in ebtables commands
Date: Thu, 01 Apr 2010 08:51:38 +0200 [thread overview]
Message-ID: <4BB4427A.3020706@pandora.be> (raw)
In-Reply-To: <x2v861e3bca1003311124sa0aa2ab6y94fa42c650ef16f8@mail.gmail.com>
agashi shipora wrote:
> I want to use L7 filter with ebtables for setting a MARK on the packet
> similar to how it is being done with iptables today.
>
> Using brouting the bridge packet can be re-directed to the routing
> path traversing the iptables.But all packets arriving on the interface
> enslaved to the bridge would have to be brouted.This may not be
> acceptable as a solution in my case.
>
> example:
> Whats available:
> iptables -t filter -A FORWARD -m layer7 --l7proto edonkey -j MARK --set-mark 3
>
> What needs to be supported:
> ebtables -t nat -A PRE-ROUTING -m layer7 --l7proto edonkey -j MARK --mark-set 3
>
> Is any work going on to port L7 filter to ebtables or does this port
> of L7 filter already exist?
>
You can use iptables to filter bridged IP traffic, so I don't see the
problem. Just make sure /proc/sys/net/bridge/bridge-nf-call-iptables
contains 1. No need for brouting.
cheers,
Bart
--
Bart De Schuymer
www.artinalgorithms.be
next prev parent reply other threads:[~2010-04-01 6:51 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-03-31 18:24 uisng L7 filter in ebtables commands agashi shipora
2010-04-01 6:51 ` Bart De Schuymer [this message]
2010-04-01 7:50 ` agashi shipora
2010-04-01 8:00 ` Jan Engelhardt
2010-04-01 9:48 ` agashi shipora
2010-04-01 10:19 ` Jan Engelhardt
2010-04-01 10:20 ` Bart De Schuymer
2010-04-01 14:14 ` agashi shipora
2010-04-01 16:09 ` /dev/rob0
2010-04-01 15:58 ` Stephen Hemminger
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4BB4427A.3020706@pandora.be \
--to=bdschuym@pandora.be \
--cc=gashipo@gmail.com \
--cc=netfilter-devel@vger.kernel.org \
--cc=netfilter@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.