• S
    nwfilter: add XML attribute to control iptables state match · 51d3fb02
    Stefan Berger 提交于
    This patch adds an optional XML attribute to a nwfilter rule to give the user control over whether the rule is supposed to be using the iptables state match or not. A rule may now look like shown in the XML below with the statematch attribute either having value '0' or 'false' (case-insensitive).
    
    [...]
    <rule action='accept' direction='in' statematch='false'>
    <tcp srcmacaddr='1:2:3:4:5:6'
               srcipaddr='10.1.2.3' srcipmask='32'
               dscp='33'
               srcportstart='20' srcportend='21'
               dstportstart='100' dstportend='1111'/>
    </rule>
    [...]
    
    I am also extending the nwfilter schema and add this attribute to a test case.
    51d3fb02
nwfilter.rng 22.6 KB