]> git.hungrycats.org Git - linux/commit
[NETFILTER]: Add iptables CONNMARK match+target
authorHarald Welte <laforge@netfilter.org>
Wed, 20 Oct 2004 14:14:41 +0000 (07:14 -0700)
committerDavid S. Miller <davem@nuts.davemloft.net>
Wed, 20 Oct 2004 14:14:41 +0000 (07:14 -0700)
commite42d291db750b2cd605ed5bfbb74e61e80b532de
tree5bf2bcb3ba14e10c78f0151966448043c4c75840
parentbd03dca44e17a4b0a3190c42ad616b59eb2ce4ec
[NETFILTER]: Add iptables CONNMARK match+target

This is the first patch, adding something similar like nfmark, but on a
per-conntrack (as opposed to per-skb) level.  Very useful especially for
asymmatric routing in combination with MASQUERADE, as often found on
home DSL setups with dymamic IP address that also have e.g. a tunnel
device with static IP.

Signed-off-by: Henrik Nordstrom <hno@marasystems.com>
Signed-off-by: Harald Welte <laforge@netfilter.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
include/linux/netfilter_ipv4/ip_conntrack.h
include/linux/netfilter_ipv4/ipt_CONNMARK.h [new file with mode: 0644]
include/linux/netfilter_ipv4/ipt_connmark.h [new file with mode: 0644]
net/ipv4/netfilter/Kconfig
net/ipv4/netfilter/Makefile
net/ipv4/netfilter/ip_conntrack_core.c
net/ipv4/netfilter/ip_conntrack_standalone.c
net/ipv4/netfilter/ipt_CONNMARK.c [new file with mode: 0644]
net/ipv4/netfilter/ipt_connmark.c [new file with mode: 0644]