summaryrefslogtreecommitdiffstats
path: root/src/parser.y
diff options
context:
space:
mode:
authorArturo Borrero <arturo.borrero.glez@gmail.com>2014-11-07 12:39:35 +0100
committerPablo Neira Ayuso <pablo@netfilter.org>2014-11-09 16:52:34 +0100
commitb5dff507ccd1c666210de51af83fa730d6baf50a (patch)
tree1ed1b94f35eb6d396a70042331a002aa79a1f7b0 /src/parser.y
parent950ae81b3aa6f8e604351042a05ad26ddad90a56 (diff)
parser: allow both nat_flags and port specification in redirect
This patch changes the parser to permit both nat_flags and port specification in the redirect expression. The resulting syntax is: % nft add rule nat prerouting redirect [port] [nat_flags] The port specification requires a bit of context regardin the transport protocol. Some examples: % nft add rule nat prerouting tcp dport 22 redirect :23 % nft add rule add prerouting udp dport 53 redirect :5353 The nat_flags argument is the last argument: % nft add rule nat prerouting tdp dport 80 redirect :8080 random The port specification can be a range: % nft add rule nat prerouting tcp dport 80 redirect :8080-8090 random While at it, the regression tests files are updated. Suggested-by: Pablo Neira Ayuso <pablo@netfilter.org> Signed-off-by: Arturo Borrero Gonzalez <arturo.borrero.glez@gmail.com> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'src/parser.y')
-rw-r--r--src/parser.y5
1 files changed, 5 insertions, 0 deletions
diff --git a/src/parser.y b/src/parser.y
index 6209e9eb..3992c6a5 100644
--- a/src/parser.y
+++ b/src/parser.y
@@ -1437,6 +1437,11 @@ redir_stmt_arg : COLON expr
{
$<stmt>0->redir.flags = $1;
}
+ | COLON expr nf_nat_flags
+ {
+ $<stmt>0->redir.proto = $2;
+ $<stmt>0->redir.flags = $3;
+ }
;
nf_nat_flags : nf_nat_flag