From 5a52e6a9cffd8e2a5d16af0fa08902ca8332190b Mon Sep 17 00:00:00 2001 From: Florian Westphal Date: Mon, 5 Nov 2018 18:58:42 +0100 Subject: extensions: test protocol and interface negation Signed-off-by: Florian Westphal --- extensions/libxt_standard.t | 3 +++ 1 file changed, 3 insertions(+) (limited to 'extensions/libxt_standard.t') diff --git a/extensions/libxt_standard.t b/extensions/libxt_standard.t index bfdedb7a..4313f7b7 100644 --- a/extensions/libxt_standard.t +++ b/extensions/libxt_standard.t @@ -3,6 +3,9 @@ ! -s 0.0.0.0 -j ACCEPT;! -s 0.0.0.0/32 -j ACCEPT;OK ! -d 0.0.0.0/32 -j ACCEPT;=;OK -s 0.0.0.0/24 -j RETURN;=;OK +-p tcp -j ACCEPT;=;OK +! -p udp -j ACCEPT;=;OK -j DROP;=;OK -j ACCEPT;=;OK -j RETURN;=;OK +! -p 0 -j ACCEPT;=;FAIL -- cgit v1.2.3