From: Mart Frauenlob <mart.frauenlob@chello.at>
To: Alex Bligh <alex@alex.org.uk>
Cc: netfilter list <netfilter@vger.kernel.org>
Subject: Re: iptables: Distinguishing packets from bridge-nf-call-iptables
Date: Wed, 05 Feb 2014 12:53:48 +0100 [thread overview]
Message-ID: <52F2264C.2060500@chello.at> (raw)
In-Reply-To: <BC2A25BE-4E4F-4270-855A-E0D092F4A7C0@alex.org.uk>
On 05.02.2014 12:24, Alex Bligh wrote:
> I am trying to run two pieces of software X and Y on a linux box.
>
> X assumes /proc/sys/net/bridge/bridge-nf-call-iptables is set to 1. I am not able to modify this.
>
> Y assumes /proc/sys/net/bridge/bridge-nf-call-iptables is set to 0. This is my software and I can modify it.
>
> I want to adapt my rules for Y so that it copes with /proc/sys/net/bridge/bridge-nf-call-iptables=1 by ignoring (in the iptables rule) any traffic which is purely bridged, and simply doing the ebtables rules on these packets.
>
> In the iptables rules, how do I differentiate ip forwarded traffic from bridged traffic? The bridge interfaces may or may not carry IP addresses.
>
-m physdev ... ?
next prev parent reply other threads:[~2014-02-05 11:53 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-02-05 11:24 iptables: Distinguishing packets from bridge-nf-call-iptables Alex Bligh
2014-02-05 11:53 ` Mart Frauenlob [this message]
2014-02-06 0:58 ` Alex Bligh
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=52F2264C.2060500@chello.at \
--to=mart.frauenlob@chello.at \
--cc=alex@alex.org.uk \
--cc=netfilter@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.