diff options
Diffstat (limited to 'extensions/libxt_ecn.txlate')
-rw-r--r-- | extensions/libxt_ecn.txlate | 23 |
1 files changed, 23 insertions, 0 deletions
diff --git a/extensions/libxt_ecn.txlate b/extensions/libxt_ecn.txlate new file mode 100644 index 00000000..9e3bd310 --- /dev/null +++ b/extensions/libxt_ecn.txlate @@ -0,0 +1,23 @@ +iptables-translate -A INPUT -m ecn --ecn-ip-ect 0 +nft add rule ip filter INPUT ip ecn not-ect counter + +iptables-translate -A INPUT -m ecn --ecn-ip-ect 1 +nft add rule ip filter INPUT ip ecn ect1 counter + +iptables-translate -A INPUT -m ecn --ecn-ip-ect 2 +nft add rule ip filter INPUT ip ecn ect0 counter + +iptables-translate -A INPUT -m ecn --ecn-ip-ect 3 +nft add rule ip filter INPUT ip ecn ce counter + +iptables-translate -A INPUT -m ecn ! --ecn-ip-ect 0 +nft add rule ip filter INPUT ip ecn != not-ect counter + +iptables-translate -A INPUT -m ecn ! --ecn-ip-ect 1 +nft add rule ip filter INPUT ip ecn != ect1 counter + +iptables-translate -A INPUT -m ecn ! --ecn-ip-ect 2 +nft add rule ip filter INPUT ip ecn != ect0 counter + +iptables-translate -A INPUT -m ecn ! --ecn-ip-ect 3 +nft add rule ip filter INPUT ip ecn != ce counter |