diff options
author | Shivani Bhardwaj <shivanib134@gmail.com> | 2015-12-20 23:43:21 +0530 |
---|---|---|
committer | Pablo Neira Ayuso <pablo@netfilter.org> | 2016-02-16 19:30:22 +0100 |
commit | 6cfa723a83d45fac52646413caba59e1233c6bae (patch) | |
tree | d9bbe3ccb2d9e51aef86b705a9b79ff510af93a5 /extensions/libxt_TPROXY.t | |
parent | 6a0c31d7ff012696b47b7b9d80b211b3d573012f (diff) |
extensions: libxt_esp: Add translation to nft
Add translation for ESP Protocol to nftables.
Examples:
$ sudo iptables-translate -A FORWARD -p esp -j ACCEPT
nft add rule ip filter FORWARD ip protocol esp counter accept
$ sudo iptables-translate -A INPUT --in-interface wan --protocol esp -j ACCEPT
nft add rule ip filter INPUT iifname wan ip protocol esp counter accept
$ sudo iptables-translate -A INPUT -p 50 -m esp --espspi 500 -j DROP
nft add rule ip filter INPUT esp spi 500 counter drop
$ sudo iptables-translate -A INPUT -p 50 -m esp --espspi 500:600 -j DROP
nft add rule ip filter INPUT esp spi 500-600 counter drop
Signed-off-by: Shivani Bhardwaj <shivanib134@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'extensions/libxt_TPROXY.t')
0 files changed, 0 insertions, 0 deletions