[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <4AEB1212.6010905@gmail.com>
Date: Fri, 30 Oct 2009 17:19:30 +0100
From: Eric Dumazet <eric.dumazet@...il.com>
To: Herbert Xu <herbert@...dor.apana.org.au>
CC: Adayadil Thomas <adayadil.thomas@...il.com>,
netdev@...r.kernel.org, Patrick McHardy <kaber@...sh.net>
Subject: Re: Connection tracking and vlan
Herbert Xu a écrit :
> On Fri, Oct 30, 2009 at 04:31:50PM +0100, Eric Dumazet wrote:
>> Same thing if you have two interfaces, eth0 & eth1 : IP conntrack tuples dont
>> include interface name/index
>
> Indeed, but imagine what happens when eth0 is the LAN and eth1 is
> the wild wild Internet. Do you really want their packets to mix?
>
No, Abayadi needs firewall rules (or RPF), before entering conntrack.
Allowing spoofed packets to come from wild Internet would be...
interesting in many aspects.
And since some setups use several links to LAN, several links to
Internet, its user policy decisions.
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Powered by blists - more mailing lists