netfilter-devel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* arbitrary address mask matching
@ 2009-08-09 23:34 Christoph A.
  2009-08-10  8:48 ` Pascal Hambourg
  0 siblings, 1 reply; 4+ messages in thread
From: Christoph A. @ 2009-08-09 23:34 UTC (permalink / raw)
  To: Netfilter Developer Mailing List; +Cc: Christoph A.

[-- Attachment #1: Type: text/plain, Size: 807 bytes --]

Hi,

the example in chapter 10.3 [1] seams to be a very handy thing, but I
couldn't reproduce it (testing it on the output chain).

I'm using v1.4.3.1/2.6.29.6 does this require v1.4.4/2.6.30?

[1] http://jengelh.medozas.de/documents/Perfect_Ruleset.pdf
(btw: thanks for this wonderful paper)


iptables -A OUTPUT -d 10.10.97.1/255.255.255.253 -m iprange --dst-range
10.10.97.1-10.10.97.7 -j REJECT

this should match on 10.10.97.1,3,5,7 but matches only 1 and 3

iptables -A OUTPUT -m iprange --dst-range 10.10.97.1-10.10.97.7 -j LOG
--log-prefix "SKIPPED:  "


nmap -sP 10.10.97.1-7

log:
SKIPPED:  ... DST=10.10.97.2
SKIPPED:  ... DST=10.10.97.4
SKIPPED:  ... DST=10.10.97.7  <--
SKIPPED:  ... DST=10.10.97.5  <--
SKIPPED:  ... DST=10.10.97.6

best regards,
Christoph A.


[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 197 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2009-08-10 15:12 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-08-09 23:34 arbitrary address mask matching Christoph A.
2009-08-10  8:48 ` Pascal Hambourg
2009-08-10  9:06   ` Christoph A.
2009-08-10 15:12     ` Jan Engelhardt

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).