summaryrefslogtreecommitdiffstats
path: root/extensions/libxt_policy.man
diff options
context:
space:
mode:
authorJan Engelhardt <jengelh@medozas.de>2011-05-12 12:46:40 +0200
committerJan Engelhardt <jengelh@medozas.de>2011-05-12 12:53:23 +0200
commit15392934cf81ef85e2a1c21380c61a7a42e260d5 (patch)
tree634aa15663249547489731d35f9a772914575fd6 /extensions/libxt_policy.man
parent449cdd6bcc8d1867bbd26ecbcae9832ab01eb04a (diff)
libxt_policy: option table fixes, improved error tracking
Most of the flags are multi-use in this extension. Also transfer --next => --strict requirement to option table. Furthermore, augment the error messages emitted from fcheck to contain the policy element number, and elaborate on what an "empty policy element" is. Signed-off-by: Jan Engelhardt <jengelh@medozas.de>
Diffstat (limited to 'extensions/libxt_policy.man')
-rw-r--r--extensions/libxt_policy.man7
1 files changed, 6 insertions, 1 deletions
diff --git a/extensions/libxt_policy.man b/extensions/libxt_policy.man
index 3500025c..1b834fa0 100644
--- a/extensions/libxt_policy.man
+++ b/extensions/libxt_policy.man
@@ -13,11 +13,16 @@ is valid in the
chains.
.TP
\fB\-\-pol\fP {\fBnone\fP|\fBipsec\fP}
-Matches if the packet is subject to IPsec processing.
+Matches if the packet is subject to IPsec processing. \fB\-\-pol none\fP
+cannot be combined with \fB\-\-strict\fP.
.TP
\fB\-\-strict\fP
Selects whether to match the exact policy or match if any rule of
the policy matches the given policy.
+.PP
+For each policy element that is to be described, one can use one or more of
+the following options. When \fB\-\-strict\fP is in effect, at least one must be
+used per element.
.TP
[\fB!\fP] \fB\-\-reqid\fP \fIid\fP
Matches the reqid of the policy rule. The reqid can be specified with