[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20191115223624.ocmnjslnsszw6ddm@salvia>
Date: Fri, 15 Nov 2019 23:36:24 +0100
From: Pablo Neira Ayuso <pablo@...filter.org>
To: Phil Sutter <phil@....cc>
Cc: netfilter-devel@...r.kernel.org, netdev@...r.kernel.org,
Eric Garver <eric@...ver.life>
Subject: Re: [nf-next PATCH] net: netfilter: Support iif matches in
POSTROUTING
On Tue, Nov 12, 2019 at 05:14:37PM +0100, Phil Sutter wrote:
> Instead of generally passing NULL to NF_HOOK_COND() for input device,
> pass skb->dev which contains input device for routed skbs.
>
> Note that iptables (both legacy and nft) reject rules with input
> interface match from being added to POSTROUTING chains, but nftables
> allows this.
Applied, thanks.
Powered by blists - more mailing lists