• S
    Enable chains with names having a known prefix · ea7c73a7
    Stefan Berger 提交于
    This patch enables chains that have a known prefix in their name.
    Known prefixes are: 'ipv4', 'ipv6', 'arp', 'rarp'. All prefixes
    are also protocols that can be evaluated on the ebtables level.
    
    Following the prefix they will be automatically connected to an interface's
    'root' chain and jumped into following the protocol they evaluate, i.e.,
    a table 'arp-xyz' will be accessed from the root table using
    
    ebtables -t nat -A <iface root table> -p arp -j I-<ifname>-arp-xyz
    
    thus generating a 'root' chain like this one here:
    
    Bridge chain: libvirt-O-vnet0, entries: 5, policy: ACCEPT
    -p IPv4 -j O-vnet0-ipv4
    -p ARP -j O-vnet0-arp
    -p 0x8035 -j O-vnet0-rarp
    -p ARP -j O-vnet0-arp-xyz
    -j DROP 
    
    where the chain 'arp-xyz' is accessed for filtering of ARP packets.
    Signed-off-by: NStefan Berger <stefanb@linux.vnet.ibm.com>
    ea7c73a7
nwfilter.rng 25.6 KB