From: Joel Newkirk <netfilter@newkirk.us>
To: netfilter@lists.netfilter.org
Subject: iptables wishes
Date: Tue, 1 Apr 2003 03:41:48 -0500 [thread overview]
Message-ID: <200304010341.48281.netfilter@newkirk.us> (raw)
I haven't started a new thread here in ages, and this is something I've
been toying with for a while. With the recent announcement of a
feature-freeze on iptables 1.2.8, this seemed a reasonable time to start
this thread. (targeting later releases, obviously, and hoping to spark
some constructive discussion :^)
I was curious to hear what people might have as a 'wishlist' for
iptables/netfilter capabilities. Every once in a while something comes
up here that simply doesn't seem to have a good solution.
My hope is that many of our personal wishes may already be possible, and
by voicing them someone who has a solution may post it. And for any
that don't presently have an answer, perhaps someone will be inspired to
create one.
Personally I have four:
1 - revamped LOG entry format, especially cleaning up MAC.
2 - completely separate netfilter logging from kernel log streams. (not
just redirecting infrequently-used kernel streams, but actual dedicated
netfilter streams)
3 - Ability to match "original DestinationIP" of a DNATted packet in
subsequent chains. Useful with a single physical interface but multiple
IPs bound to it.
4 - addition of support for a REM field in rules. Would do nothing
whatsoever except print the specified REMark text at the end of the rule
in -L listings. Something like:
iptables -A INPUT -p tcp --dport 22 -s a.b.c.d -j ACCEPT -REM JoelSSH
So that a -L listing could be easier & quicker to decipher sometimes. It
would also allow "iptables -L -v -n | grep Joel" to list only rules, in
all chains, with "Joel" in the comment.
j
next reply other threads:[~2003-04-01 8:41 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-04-01 8:41 Joel Newkirk [this message]
2003-04-01 10:17 ` iptables wishes Martin Josefsson
2003-04-01 15:13 ` Joel Newkirk
2003-04-06 3:57 ` AW: " Michael Schoen
-- strict thread matches above, loose matches on Subject: below --
2003-04-01 9:48 mailinglists
2003-04-01 14:32 ` Ivano Proietti Mucci
2003-04-01 15:35 ` Joel Newkirk
2003-04-01 9:58 Michael Klinteberg
2003-04-01 14:22 ` Joel Newkirk
2003-04-02 16:54 Alex McCubbin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200304010341.48281.netfilter@newkirk.us \
--to=netfilter@newkirk.us \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox