All of lore.kernel.org
 help / color / mirror / Atom feed
* macipmap (ipset) matching
@ 2010-09-28 21:33 Mr Dash Four
  2010-09-29  7:18 ` Jozsef Kadlecsik
  0 siblings, 1 reply; 3+ messages in thread
From: Mr Dash Four @ 2010-09-28 21:33 UTC (permalink / raw)
  To: netfilter

I am trying to employ and use this, but am unable to get any match 
whatsoever. I have registered my own (internal) network and the relevant 
mac addresses for each interface, but no joy. What could be the problem? 
Has anybody actually tried this?

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: macipmap (ipset) matching
  2010-09-28 21:33 macipmap (ipset) matching Mr Dash Four
@ 2010-09-29  7:18 ` Jozsef Kadlecsik
  2010-09-29 10:01   ` Mr Dash Four
  0 siblings, 1 reply; 3+ messages in thread
From: Jozsef Kadlecsik @ 2010-09-29  7:18 UTC (permalink / raw)
  To: Mr Dash Four; +Cc: netfilter

On Tue, 28 Sep 2010, Mr Dash Four wrote:

> I am trying to employ and use this, but am unable to get any match whatsoever.
> I have registered my own (internal) network and the relevant mac addresses for
> each interface, but no joy. What could be the problem? Has anybody actually
> tried this?

Could you describe exactly what do you try to do? That is the set elements 
to be matched and the iptables rules you entered. Also, please note the 
"set" match and "SET" target netfilter kernel modules always use the
source MAC address from the packet.

The ipset source tree contains a testsuite with tests against all set 
types.

Best regards,
Jozsef
-
E-mail  : kadlec@blackhole.kfki.hu, kadlec@mail.kfki.hu
PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt
Address : KFKI Research Institute for Particle and Nuclear Physics
          H-1525 Budapest 114, POB. 49, Hungary

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: macipmap (ipset) matching
  2010-09-29  7:18 ` Jozsef Kadlecsik
@ 2010-09-29 10:01   ` Mr Dash Four
  0 siblings, 0 replies; 3+ messages in thread
From: Mr Dash Four @ 2010-09-29 10:01 UTC (permalink / raw)
  To: Jozsef Kadlecsik; +Cc: netfilter


>> I am trying to employ and use this, but am unable to get any match whatsoever.
>> I have registered my own (internal) network and the relevant mac addresses for
>> each interface, but no joy. What could be the problem? Has anybody actually
>> tried this?
>>     
>
> Could you describe exactly what do you try to do?
I am creating a match rule (I am using Shorewall), which matches both IP 
and mac addresses, but this match is never triggered, hence my initial 
query.

> The ipset source tree contains a testsuite with tests against all set 
> types.
>   
Thanks for that - I will look at it and see if I could use it here.


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2010-09-29 10:01 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-09-28 21:33 macipmap (ipset) matching Mr Dash Four
2010-09-29  7:18 ` Jozsef Kadlecsik
2010-09-29 10:01   ` Mr Dash Four

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.