diff options
author | Pablo Neira Ayuso <pablo@netfilter.org> | 2021-03-24 17:54:33 +0100 |
---|---|---|
committer | Pablo Neira Ayuso <pablo@netfilter.org> | 2021-03-24 17:55:07 +0100 |
commit | f699e4c06a26b4977f4a5d220a0c5260b71d6433 (patch) | |
tree | 4b5dfe546d3e46c3421d9ad491cc0cedd53d1a98 /doc/statements.txt | |
parent | 8c226fabc63f21c00ea07b7d484053f797ce994c (diff) |
doc: no need to define a set in ct state
ct state are flags, no need to define a set for this.
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'doc/statements.txt')
-rw-r--r-- | doc/statements.txt | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/doc/statements.txt b/doc/statements.txt index c1fd5e55..6fc0bda0 100644 --- a/doc/statements.txt +++ b/doc/statements.txt @@ -570,7 +570,7 @@ will be out-of-flow packets that were not matched by SYNPROXY. table ip x { chain z { type filter hook input priority filter; policy accept; - ct state { invalid, untracked } synproxy mss 1460 wscale 9 timestamp sack-perm + ct state invalid, untracked synproxy mss 1460 wscale 9 timestamp sack-perm ct state invalid drop } } |