summaryrefslogtreecommitdiffstats
path: root/tests/py/inet/synproxy.t
Commit message (Collapse)AuthorAgeFilesLines
* src: introduce SYNPROXY matchingFernando Fernandez Mancera2019-07-171-0/+13
Add support for "synproxy" statement. For example (for TCP port 8888): table ip x { chain y { type filter hook prerouting priority raw; policy accept; tcp dport 8888 tcp flags syn notrack } chain z { type filter hook input priority filter; policy accept; tcp dport 8888 ct state invalid,untracked synproxy mss 1460 wscale 7 timestamp sack-perm ct state invalid drop } } Signed-off-by: Fernando Fernandez Mancera <ffmancera@riseup.net> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>