1. 26 Jan, 2011 1 commit
    • Jan Engelhardt's avatar
      netfilter: xt_connlimit: pick right dstaddr in NAT scenario · ad86e1f2
      Jan Engelhardt authored
      xt_connlimit normally records the "original" tuples in a hashlist
      (such as "1.2.3.4 -> 5.6.7.8"), and looks in this list for iph->daddr
      when counting.
      
      When the user however uses DNAT in PREROUTING, looking for
      iph->daddr -- which is now 192.168.9.10 -- will not match. Thus in
      daddr mode, we need to record the reverse direction tuple
      ("192.168.9.10 -> 1.2.3.4") instead. In the reverse tuple, the dst
      addr is on the src side, which is convenient, as count_them still uses
      &conn->tuple.src.u3.
      Signed-off-by: default avatarJan Engelhardt <jengelh@medozas.de>
      ad86e1f2
  2. 22 Jan, 2011 2 commits
  3. 20 Jan, 2011 21 commits
  4. 19 Jan, 2011 16 commits