From bd9445863cb7586dfc9bafa64013d8636f838444 Mon Sep 17 00:00:00 2001 From: Florian Westphal Date: Tue, 14 Mar 2017 20:12:30 +0100 Subject: files: provide 'raw' table equivalent useful for the 'ct zone set' statement, it has to be done before the conntrack lookup but preferrably after the defragmention hook. In iptables, the functionality resides in the CT target which is restricted to the raw table. This provides the skeleton for nft. Signed-off-by: Florian Westphal --- files/nftables/Makefile.am | 4 +++- files/nftables/ipv4-raw | 6 ++++++ files/nftables/ipv6-raw | 6 ++++++ 3 files changed, 15 insertions(+), 1 deletion(-) create mode 100644 files/nftables/ipv4-raw create mode 100644 files/nftables/ipv6-raw (limited to 'files/nftables') diff --git a/files/nftables/Makefile.am b/files/nftables/Makefile.am index 1378e2b6..a4c7ac7c 100644 --- a/files/nftables/Makefile.am +++ b/files/nftables/Makefile.am @@ -5,9 +5,11 @@ dist_pkgsysconf_DATA = bridge-filter \ ipv4-filter \ ipv4-mangle \ ipv4-nat \ + ipv4-raw \ ipv6-filter \ ipv6-mangle \ - ipv6-nat + ipv6-nat \ + ipv6-raw install-data-hook: ${SED} -i 's|@sbindir[@]|${sbindir}/|g' ${DESTDIR}${pkgsysconfdir}/* diff --git a/files/nftables/ipv4-raw b/files/nftables/ipv4-raw new file mode 100644 index 00000000..19773ee8 --- /dev/null +++ b/files/nftables/ipv4-raw @@ -0,0 +1,6 @@ +#! @sbindir@nft -f + +table raw { + chain prerouting { type filter hook prerouting priority -300; } + chain output { type filter hook output priority -300; } +} diff --git a/files/nftables/ipv6-raw b/files/nftables/ipv6-raw new file mode 100644 index 00000000..5ee56a83 --- /dev/null +++ b/files/nftables/ipv6-raw @@ -0,0 +1,6 @@ +#! @sbindir@nft -f + +table ip6 raw { + chain prerouting { type filter hook prerouting priority -300; } + chain output { type filter hook output priority -300; } +} -- cgit v1.2.3