summaryrefslogtreecommitdiffstats
path: root/include/libiptc
diff options
context:
space:
mode:
authorShivani Bhardwaj <shivanib134@gmail.com>2016-03-03 00:45:55 +0530
committerPablo Neira Ayuso <pablo@netfilter.org>2016-03-03 13:22:30 +0100
commit3d7d1afe43f6fb1e466671c8d2ce7517079b466a (patch)
tree46e1081f82ee57aae072fd715d57ff9b16acc92b /include/libiptc
parent6d4b93485055a83639806f4b1d085899f47a198a (diff)
extensions: libxt_owner: Add translation to nft
Add translation for module owner to nftables. Full translation of this match awaits the support for --socket-exists option. Examples: $ sudo iptables-translate -t nat -A OUTPUT -p tcp --dport 80 -m owner --uid-owner root -j ACCEPT nft add rule ip nat OUTPUT tcp dport 80 skuid 0 counter accept $ sudo iptables-translate -t nat -A OUTPUT -p tcp --dport 80 -m owner --gid-owner 0-10 -j ACCEPT nft add rule ip nat OUTPUT tcp dport 80 skgid 0-10 counter accept $ sudo iptables-translate -t nat -A OUTPUT -p tcp --dport 80 -m owner ! --uid-owner shivani -j ACCEPT nft add rule ip nat OUTPUT tcp dport 80 skuid != 1000 counter accept Signed-off-by: Shivani Bhardwaj <shivanib134@gmail.com> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'include/libiptc')
0 files changed, 0 insertions, 0 deletions