diff options
author | Liping Zhang <zlpnobody@163.com> | 2016-12-25 20:12:55 +0800 |
---|---|---|
committer | Pablo Neira Ayuso <pablo@netfilter.org> | 2017-01-16 14:09:47 +0100 |
commit | e3ec9362f0edad08834cb8ba66bc45fdb0bf33f5 (patch) | |
tree | 383e1e10a0787e0cf10477cc493a8ea9a9ebb458 /src/scanner.l | |
parent | 5d6e721c8fe31e14ddedb1a642553d072ec99bd1 (diff) |
ct: add average bytes per packet counter support
Similar to connbytes extension in iptables, now you can use it to match
average bytes per packet a connection has transferred so far.
For example, match avgpkt in "BOTH" diretion:
# nft add rule x y ct avgpkt \> 100
Match avgpkt in reply direction:
# nft add rule x y ct reply avgpkt \< 900
Or match avgpkt in original direction:
# nft add rule x y ct original avgpkt \> 200
Signed-off-by: Liping Zhang <zlpnobody@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'src/scanner.l')
-rw-r--r-- | src/scanner.l | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/src/scanner.l b/src/scanner.l index 6b441b54..d0d25ea9 100644 --- a/src/scanner.l +++ b/src/scanner.l @@ -294,6 +294,7 @@ addrstring ({macaddr}|{ip4addr}|{ip6addr}) "name" { return NAME; } "packets" { return PACKETS; } "bytes" { return BYTES; } +"avgpkt" { return AVGPKT; } "counters" { return COUNTERS; } "quotas" { return QUOTAS; } |