netfilter-devel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH 0/2] Interface groups, round two
       [not found] ` <ifgroup-20071018-120757-1192702077-panther@balabit.hu>
@ 2007-10-18 10:13 Laszlo Attila Toth
       [not found] ` <ifgroup-20071018-120757-1192702077-panther@balabit.hu>
  0 siblings, 1 reply; 31+ messages in thread
From: Laszlo Attila Toth @ 2007-10-18 10:13 UTC (permalink / raw)
  To: netdev, netfilter-devel; +Cc: Laszlo Attila Toth

Hello,

Here is the new version of ifgroup patches.

The interface group value is u_int32_t in net_device which should be enough.
Previously it was an int.

Usage:
   ip link set eth0 group 4
but currently it cannot be unset, only changed to another value.

In /etc/iproute2/rt_ifgroup each value may have a symbolic name.

Netfilter part: xt_ifgroup module for both IPv4 and IPv6. Iptables usage:
   iptables -A INPUT -m ifgroup --in-ifgroup 4/0xf -j ACCEPT
   iptables -A FORWARD -m ifgroup --in-ifgroup 4 --out-ifgroup 5 -j ACCEPT
   ...

in the FORWARD chain both input and output interface group value should be matched
(with optional masks).

The following patches are:
  kernel: core part
  kernel: netfilter module, ifgroup match
  iproute2: showing and set ifgroup value
  iptables: ifgroup match
--
Laszlo Attila Toth

^ permalink raw reply	[flat|nested] 31+ messages in thread
* [PATCH 0/2] Interface groups, round two
       [not found] ` <ifgroup-20071018-120757-1192702077-panther@balabit.hu>
@ 2007-10-18 10:15 Laszlo Attila Toth
  0 siblings, 0 replies; 31+ messages in thread
From: Laszlo Attila Toth @ 2007-10-18 10:15 UTC (permalink / raw)
  To: netdev, netfilter-devel; +Cc: Laszlo Attila Toth

Hello,

Here is the new version of ifgroup patches.

The interface group value is u_int32_t in net_device which should be enough.
Previously it was an int.

Usage:
   ip link set eth0 group 4
but currently it cannot be unset, only changed to another value.

In /etc/iproute2/rt_ifgroup each value may have a symbolic name.

Netfilter part: xt_ifgroup module for both IPv4 and IPv6. Iptables usage:
   iptables -A INPUT -m ifgroup --in-ifgroup 4/0xf -j ACCEPT
   iptables -A FORWARD -m ifgroup --in-ifgroup 4 --out-ifgroup 5 -j ACCEPT
   ...

in the FORWARD chain both input and output interface group value should be matched
(with optional masks).

The following patches are:
  kernel: core part
  kernel: netfilter module, ifgroup match
  iproute2: showing and set ifgroup value
  iptables: ifgroup match
--
Laszlo Attila Toth

^ permalink raw reply	[flat|nested] 31+ messages in thread

end of thread, other threads:[~2007-10-19  8:57 UTC | newest]

Thread overview: 31+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
     [not found] <ifgroup.20071015.1192520046.panther@balabit.hu>
2007-10-16  8:01 ` [PATCH 0/2] Interface groups Laszlo Attila Toth
2007-10-16  8:50   ` Philip Craig
2007-10-16  9:47     ` Laszlo Attila Toth
2007-10-16  8:01 ` Laszlo Attila Toth
     [not found] ` <1824b3d462b1d85aaf33941cf082c4e018d5bff7.1192460167.git.panther@balabit.hu>
2007-10-16  8:01   ` [PATCH 1/2] Interface group: core (netlink) part Laszlo Attila Toth
2007-10-16  8:01   ` Laszlo Attila Toth
2007-10-16  8:34     ` Patrick McHardy
     [not found]   ` <661f8f2fdb86cc70bdefd12403ecb0eaa7cfadd6.1192460168.git.panther@balabit.hu>
2007-10-16  8:01     ` [PATCH 2/2] Interface group match - netfilter part Laszlo Attila Toth
2007-10-16  8:01     ` Laszlo Attila Toth
2007-10-16  8:30       ` Patrick McHardy
2007-10-16  9:46         ` Laszlo Attila Toth
2007-10-16 14:46         ` Jan Engelhardt
2007-10-17  9:08         ` Laszlo Attila Toth
2007-10-17  9:11           ` Patrick McHardy
     [not found] ` <a6713ba13c49b7fa20073d8abf1862480c2799e0.1192457385.git.panther@balabit.hu>
2007-10-16  8:01   ` [IPROUTE2 PATCH] Interface group as new ip link option Laszlo Attila Toth
2007-10-16  8:01   ` Laszlo Attila Toth
2007-10-16  8:38     ` Patrick McHardy
2007-10-16  9:33       ` Laszlo Attila Toth
2007-10-16  9:03   ` Resend: " Laszlo Attila Toth
2007-10-16  9:03   ` Laszlo Attila Toth
2007-10-16  9:11     ` Patrick McHardy
2007-10-16 10:45   ` jamal
2007-10-16 11:05     ` Laszlo Attila Toth
2007-10-16 11:26       ` jamal
2007-10-16 11:47         ` Laszlo Attila Toth
2007-10-16 12:08           ` jamal
2007-10-18 10:13 [PATCH 0/2] Interface groups, round two Laszlo Attila Toth
     [not found] ` <ifgroup-20071018-120757-1192702077-panther@balabit.hu>
     [not found]   ` <4e88bea1c0065fada9181e9b668a91c6c3fd8796.1192695706.git.panther@balabit.hu>
2007-10-18 10:13     ` [PATCH 1/2] Interface group: core (netlink) part Laszlo Attila Toth
2007-10-18 10:15     ` Laszlo Attila Toth
2007-10-18 10:22       ` Patrick McHardy
2007-10-19  8:57         ` Laszlo Attila Toth
2007-10-18 10:15     ` Laszlo Attila Toth
  -- strict thread matches above, loose matches on Subject: below --
2007-10-18 10:15 [PATCH 0/2] Interface groups, round two Laszlo Attila Toth

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).