diff options
-rw-r--r-- | src/parser.y | 5 | ||||
-rw-r--r-- | tests/regression/ip/redirect.t | 14 | ||||
-rw-r--r-- | tests/regression/ip6/redirect.t | 8 |
3 files changed, 19 insertions, 8 deletions
diff --git a/src/parser.y b/src/parser.y index 6209e9eb..3992c6a5 100644 --- a/src/parser.y +++ b/src/parser.y @@ -1437,6 +1437,11 @@ redir_stmt_arg : COLON expr { $<stmt>0->redir.flags = $1; } + | COLON expr nf_nat_flags + { + $<stmt>0->redir.proto = $2; + $<stmt>0->redir.flags = $3; + } ; nf_nat_flags : nf_nat_flag diff --git a/tests/regression/ip/redirect.t b/tests/regression/ip/redirect.t index f69fd07c..cb230e2b 100644 --- a/tests/regression/ip/redirect.t +++ b/tests/regression/ip/redirect.t @@ -24,11 +24,15 @@ tcp dport 39128 redirect :993;ok redirect :1234;fail redirect :12341111;fail -# invalid arguments -tcp dport 9128 redirect :993 random;fail -tcp dport 9128 redirect :993 random-fully;fail -tcp dport 9128 redirect persistent :123;fail -tcp dport 9128 redirect random,persistent :123;fail +# both port and nf_nat flags +tcp dport 9128 redirect :993 random;ok +tcp dport 9128 redirect :993 random-fully;ok +tcp dport 9128 redirect :123 persistent;ok +tcp dport 9128 redirect :123 random,persistent;ok + +# nf_nat flags is the last argument +udp dport 1234 redirect random :123;fail +udp dport 21234 redirect persistent,random-fully :431;fail # redirect is a terminal statement tcp dport 22 redirect counter packets 0 bytes 0 accept;fail diff --git a/tests/regression/ip6/redirect.t b/tests/regression/ip6/redirect.t index d9728714..dce4794a 100644 --- a/tests/regression/ip6/redirect.t +++ b/tests/regression/ip6/redirect.t @@ -25,9 +25,11 @@ tcp dport 39128 redirect :993;ok redirect :1234;fail redirect :12341111;fail -# invalid arguments -tcp dport 9128 redirect :993 random;fail -tcp dport 9128 redirect :993 random-fully;fail +# both port and nf_nat flags +tcp dport 9128 redirect :993 random;ok +tcp dport 9128 redirect :993 random-fully,persistent;ok + +# nf_nat flags are the last argument tcp dport 9128 redirect persistent :123;fail tcp dport 9128 redirect random,persistent :123;fail |