Linux Advanced Routing and Traffic Control list
 help / color / mirror / Atom feed
* [LARTC] iptables marks
@ 2007-04-15  4:25 Alejandro Ramos Encinosa
  2007-04-22  0:04 ` Nelson Castillo
  2007-04-23 11:47 ` Padam J Singh
  0 siblings, 2 replies; 3+ messages in thread
From: Alejandro Ramos Encinosa @ 2007-04-15  4:25 UTC (permalink / raw)
  To: lartc

Hi all!!

I was trying to figure out how iptables marks work. I thought that a packet 
could just be marked once into a chain (if the packet matchs the criteria, 
then it the action is applied, and that's all for the packet into this 
chain), but I was wrong: I did

iptables -t mangle -A INPUT -i eth0 -j MARK --set-mark 7
iptables -t mangle -A INPUT -i eth0 -j MARK --set-mark 8

and then I did `iptables -t mangle -L -x -v' and I got

Chain INPUT (policy ACCEPT 9565560 packets, 4954706655 bytes)
 pkts bytes target prot opt in   out source   destination
   45 31630  MARK     0 --  eth0 any anywhere anywhere    MARK set 0x7
   45 31630  MARK     0 --  eth0 any anywhere anywhere    MARK set 0x8

Can someone tell me how can I be sure one packet will just be marked once into 
the chain?
_______________________________________________
LARTC mailing list
LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [LARTC] iptables marks
  2007-04-15  4:25 [LARTC] iptables marks Alejandro Ramos Encinosa
@ 2007-04-22  0:04 ` Nelson Castillo
  2007-04-23 11:47 ` Padam J Singh
  1 sibling, 0 replies; 3+ messages in thread
From: Nelson Castillo @ 2007-04-22  0:04 UTC (permalink / raw)
  To: lartc

> iptables -t mangle -A INPUT -i eth0 -j MARK --set-mark 7
> iptables -t mangle -A INPUT -i eth0 -j MARK --set-mark 8
>
> and then I did `iptables -t mangle -L -x -v' and I got
>
> Chain INPUT (policy ACCEPT 9565560 packets, 4954706655 bytes)
>  pkts bytes target prot opt in   out source   destination
>    45 31630  MARK     0 --  eth0 any anywhere anywhere    MARK set 0x7
>    45 31630  MARK     0 --  eth0 any anywhere anywhere    MARK set 0x8
>
> Can someone tell me how can I be sure one packet will just be marked once into
> the chain?

I would try the following (untested) rules:

iptables -t mangle -A INPUT -i eth0 -j MARK --set-mark 7
iptables -t mangle -A INPUT -i eth0 -j RETURN
iptables -t mangle -A INPUT -i eth0 -j MARK --set-mark 8

I guess you will never get the second mark.

Regards,
Nelson.-


-- 
http://arhuaco.org
http://emQbit.com
_______________________________________________
LARTC mailing list
LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [LARTC] iptables marks
  2007-04-15  4:25 [LARTC] iptables marks Alejandro Ramos Encinosa
  2007-04-22  0:04 ` Nelson Castillo
@ 2007-04-23 11:47 ` Padam J Singh
  1 sibling, 0 replies; 3+ messages in thread
From: Padam J Singh @ 2007-04-23 11:47 UTC (permalink / raw)
  To: lartc

[-- Attachment #1: Type: text/html, Size: 1731 bytes --]

[-- Attachment #2: Type: text/plain, Size: 143 bytes --]

_______________________________________________
LARTC mailing list
LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2007-04-23 11:47 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-04-15  4:25 [LARTC] iptables marks Alejandro Ramos Encinosa
2007-04-22  0:04 ` Nelson Castillo
2007-04-23 11:47 ` Padam J Singh

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox