From mboxrd@z Thu Jan 1 00:00:00 1970 From: Steve Wright Date: Fri, 29 Aug 2003 23:55:00 +0000 Subject: Re: [LARTC] Layer 7 application blocking via tc/iptables? Message-Id: List-Id: References: In-Reply-To: MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: lartc@vger.kernel.org On Sat, 2003-08-30 at 11:24, Martin A. Brown wrote: > : > You can place the fwmark on one machine, and then > : > iptables block it on another if necessary. > : > : Can you do that? > > No. > > : AFAIK, the fwmark disappears when it leaves the machine. > > This is accurate. The fwmark is metadata and is only available on the box > where the packet has been marked. woops. thanks for the correction, Folks. cheers, Steve _______________________________________________ LARTC mailing list / LARTC@mailman.ds9a.nl http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/