netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* IPv6 multicast (MLD,IGMP) code bypasses netfilter hooks
@ 2003-11-22  9:03 Harald Welte
  2003-11-23 23:43 ` David S. Miller
  0 siblings, 1 reply; 4+ messages in thread
From: Harald Welte @ 2003-11-22  9:03 UTC (permalink / raw)
  To: netdev; +Cc: Netfilter Development Mailinglist

[-- Attachment #1: Type: text/plain, Size: 901 bytes --]

Hi!

At least to me it was not known (until very recently) that the IPv6
multicast code in net/ipv6/mcast.c bypasses the netfilter hooks - but it
does.

I don't have the time to work on this right now, just wanted to drop a
note to netdev that people are aware of this issue.

This basically means that you cannot do packet filtering with ip6tables
on outgoing MLD packets.

If anyone wants to write a patch before I get the time:  Feel free to do
so.

Dave: I think this would be post 2.6.0 stuff, wouldn't it?

-- 
- Harald Welte <laforge@netfilter.org>             http://www.netfilter.org/
============================================================================
  "Fragmentation is like classful addressing -- an interesting early
   architectural error that shows how much experimentation was going
   on while IP was being designed."                    -- Paul Vixie

[-- Attachment #2: Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2003-12-04 18:37 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-11-22  9:03 IPv6 multicast (MLD,IGMP) code bypasses netfilter hooks Harald Welte
2003-11-23 23:43 ` David S. Miller
2003-12-04  9:01   ` [PATCH 2.4.x] " Harald Welte
2003-12-04 18:37     ` David S. Miller

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).