All of lore.kernel.org
 help / color / mirror / Atom feed
* Permit *any* destination port from source ip
@ 2009-01-19 20:11 Simon Labrecque
  2009-01-19 20:14 ` Jan Engelhardt
  0 siblings, 1 reply; 5+ messages in thread
From: Simon Labrecque @ 2009-01-19 20:11 UTC (permalink / raw)
  To: netfilter-devel

Hi,

   I would like to have a specific connection act like an "authentication"
service; that is, when a connection to a specific port is made and once the
required data has passed between the 2 hosts, the client is now
authenticated, permitting access to other network services which are flagged
with the RELATED state (and not the NEW one).

   I implemented this in a very simple conntrack module. For example, I can
use something like when the module is in place:

iptables -A INPUT -p tcp --dport 22 -m state --state ESTABLISHED,RELATED -j
ACCEPT

   ...and it works once the "parent" connection has "authenticated" the
client.

   However, currently it seems I can only specify 1 single destination port
in the expectation (this would be port 22 in my example above), wherever I
would like to be able to support *any* port (as we can with the source
port). The filtering would then be made using subsequent iptables rules.

   Is this possible? It seems it was possible a while ago (while
exp->mask.dst was still present), but this was removed and I don't see how I
can achieve the same functionality with the current structures. Am I missing
something?


   Thanks a lot!
-- 
Simon Labrecque



^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2009-01-19 21:26 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-01-19 20:11 Permit *any* destination port from source ip Simon Labrecque
2009-01-19 20:14 ` Jan Engelhardt
2009-01-19 20:27   ` Simon Labrecque
2009-01-19 20:34     ` Jan Engelhardt
2009-01-19 21:26       ` Simon Labrecque

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.