netfilter-devel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* bug in iptables
@ 2008-02-14 18:38 justin joseph
  2008-02-15  6:50 ` justin joseph
  0 siblings, 1 reply; 7+ messages in thread
From: justin joseph @ 2008-02-14 18:38 UTC (permalink / raw)
  To: netfilter-devel

Hi,

I were testing shorewall with some configuration and found a bug in
shorewall version 3.4.4.

It seems to be there in iptables as well.

23:51 < justin007> I were testing shorewall and got a bug which seems
to be there in netfilter as well.
23:51 < justin007> iptables -t mangle -A tcpost -i lan1 -s
192.168.10.10 -o wan1 -p tcp --dport 22 -j CLASSIFY --set-class 1:11
23:52 < justin007> in tcpost the -i interface name is invalid,
iptables takes it though.
23:53 < jengelh> interesting
23:53 < jengelh> actually
23:53 < jengelh> ...
23:55 < jengelh> and, is it bad? no.
23:55 < jengelh> it does not crash the machine so all is fine for now
23:57 < justin007> yes it does not crach the machine. But it matches
all ports, *. which is not expected behaviour. man page does say that
the -i interfacenmae option is valid only in pre,
                   foreward, input chains
23:57 < justin007> Just wanted to mention this.
23:59 < jengelh> right
23:59 < jengelh> post it to the mailing list  (or I will do) so noone
forgets about it
Day changed to 15 Feb 2008
00:00 < justin007> please do post, I would need to join the list in
the first place :-)
00:01 < jengelh> you don't need to subscribe
00:01 < jengelh> just post to netfilter-devel@vger
00:01 < justin007> ok, I will post.
00:02 < jengelh> "Use of interface specification (e.g. -i) is not
checked against hooks when custom chain is used"
00:02 < jengelh> iptables -N foo; iptables -A foo -i eth0; iptables -A
OUTPUT -j foo;
00:03 < jengelh> That's all :)
00:03 < jengelh> short, sweet and to the point
00:05 < justin007> where is that from, I don't see it with man iptables
00:05 < jengelh> oh I just wrote that
00:05 < jengelh> that's what I would have written into the mail
00:05 < justin007> :-)

-justin

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2008-02-27 12:07 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-02-14 18:38 bug in iptables justin joseph
2008-02-15  6:50 ` justin joseph
2008-02-19 12:28   ` Patrick McHardy
2008-02-22  7:26     ` justin joseph
2008-02-22 14:08       ` Patrick McHardy
2008-02-22 14:47         ` Patrick McHardy
2008-02-27 12:07           ` Patrick McHardy

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).