authorPhil Sutter <>2019-02-21 15:38:47 +0100
committerFlorian Westphal <>2019-02-22 17:00:44 +0100
extensions: AUDIT: Document ineffective --type option
Signed-off-by: Phil Sutter <> Signed-off-by: Florian Westphal <>
@@ -3,12 +3,14 @@ It can be used to record accepted, dropped, and rejected packets. See
auditd(8) for additional details.
\fB\-\-type\fP {\fBaccept\fP|\fBdrop\fP|\fBreject\fP}
-Set type of audit record.
+Set type of audit record. Starting with linux-4.12, this option has no effect
+on generated audit messages anymore. It is still accepted by iptables for
+compatibility reasons, but ignored.
iptables \-N AUDIT_DROP
-iptables \-A AUDIT_DROP \-j AUDIT \-\-type drop
+iptables \-A AUDIT_DROP \-j AUDIT
iptables \-A AUDIT_DROP \-j DROP