* [PATCH nf] netfilter: nftables: onlly allow in/output for arp packets
@ 2017-07-07 11:29 Florian Westphal
2017-07-17 15:08 ` Pablo Neira Ayuso
0 siblings, 1 reply; 2+ messages in thread
From: Florian Westphal @ 2017-07-07 11:29 UTC (permalink / raw)
To: netfilter-devel; +Cc: Florian Westphal
arp packets cannot be forwarded.
They can be bridged, but then they can be filtered using
either ebtables or nftables bridge family.
The bridge netfilter exposes a "call-arptables" switch which
pushes packets into arptables, but lets not expose this for nftables, so better
close this asap.
Signed-off-by: Florian Westphal <fw@strlen.de>
---
net/ipv4/netfilter/nf_tables_arp.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/net/ipv4/netfilter/nf_tables_arp.c b/net/ipv4/netfilter/nf_tables_arp.c
index 805c8dd..4bbc273 100644
--- a/net/ipv4/netfilter/nf_tables_arp.c
+++ b/net/ipv4/netfilter/nf_tables_arp.c
@@ -72,8 +72,7 @@ static const struct nf_chain_type filter_arp = {
.family = NFPROTO_ARP,
.owner = THIS_MODULE,
.hook_mask = (1 << NF_ARP_IN) |
- (1 << NF_ARP_OUT) |
- (1 << NF_ARP_FORWARD),
+ (1 << NF_ARP_OUT),
};
static int __init nf_tables_arp_init(void)
--
2.9.4
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH nf] netfilter: nftables: onlly allow in/output for arp packets
2017-07-07 11:29 [PATCH nf] netfilter: nftables: onlly allow in/output for arp packets Florian Westphal
@ 2017-07-17 15:08 ` Pablo Neira Ayuso
0 siblings, 0 replies; 2+ messages in thread
From: Pablo Neira Ayuso @ 2017-07-17 15:08 UTC (permalink / raw)
To: Florian Westphal; +Cc: netfilter-devel
On Fri, Jul 07, 2017 at 01:29:03PM +0200, Florian Westphal wrote:
> arp packets cannot be forwarded.
>
> They can be bridged, but then they can be filtered using
> either ebtables or nftables bridge family.
>
> The bridge netfilter exposes a "call-arptables" switch which
> pushes packets into arptables, but lets not expose this for nftables, so better
> close this asap.
Applied, thanks.
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2017-07-17 15:08 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-07-07 11:29 [PATCH nf] netfilter: nftables: onlly allow in/output for arp packets Florian Westphal
2017-07-17 15:08 ` Pablo Neira Ayuso
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).