netfilter: nf_conntrack: add support for "conntrack zones"
Normally, each connection needs a unique identity. Conntrack zones allow
to specify a numerical zone using the CT target, connections in different
zones can use the same identity.
Example:
iptables -t raw -A PREROUTING -i veth0 -j CT --zone 1
iptables -t raw -A OUTPUT -o veth1 -j CT --zone 1
Signed-off-by:
Patrick McHardy <kaber@trash.net>
Showing
- include/linux/netfilter/xt_CT.h 1 addition, 1 deletioninclude/linux/netfilter/xt_CT.h
- include/net/ip.h 3 additions, 0 deletionsinclude/net/ip.h
- include/net/ipv6.h 3 additions, 0 deletionsinclude/net/ipv6.h
- include/net/netfilter/nf_conntrack.h 3 additions, 2 deletionsinclude/net/netfilter/nf_conntrack.h
- include/net/netfilter/nf_conntrack_core.h 2 additions, 1 deletioninclude/net/netfilter/nf_conntrack_core.h
- include/net/netfilter/nf_conntrack_expect.h 6 additions, 3 deletionsinclude/net/netfilter/nf_conntrack_expect.h
- include/net/netfilter/nf_conntrack_extend.h 2 additions, 0 deletionsinclude/net/netfilter/nf_conntrack_extend.h
- include/net/netfilter/nf_conntrack_zones.h 23 additions, 0 deletionsinclude/net/netfilter/nf_conntrack_zones.h
- net/ipv4/netfilter/nf_conntrack_l3proto_ipv4.c 2 additions, 1 deletionnet/ipv4/netfilter/nf_conntrack_l3proto_ipv4.c
- net/ipv4/netfilter/nf_conntrack_proto_icmp.c 5 additions, 3 deletionsnet/ipv4/netfilter/nf_conntrack_proto_icmp.c
- net/ipv4/netfilter/nf_defrag_ipv4.c 9 additions, 3 deletionsnet/ipv4/netfilter/nf_defrag_ipv4.c
- net/ipv4/netfilter/nf_nat_core.c 14 additions, 10 deletionsnet/ipv4/netfilter/nf_nat_core.c
- net/ipv4/netfilter/nf_nat_pptp.c 2 additions, 1 deletionnet/ipv4/netfilter/nf_nat_pptp.c
- net/ipv6/netfilter/nf_conntrack_l3proto_ipv6.c 9 additions, 3 deletionsnet/ipv6/netfilter/nf_conntrack_l3proto_ipv6.c
- net/ipv6/netfilter/nf_conntrack_proto_icmpv6.c 5 additions, 3 deletionsnet/ipv6/netfilter/nf_conntrack_proto_icmpv6.c
- net/netfilter/Kconfig 13 additions, 0 deletionsnet/netfilter/Kconfig
- net/netfilter/nf_conntrack_core.c 82 additions, 27 deletionsnet/netfilter/nf_conntrack_core.c
- net/netfilter/nf_conntrack_expect.c 14 additions, 7 deletionsnet/netfilter/nf_conntrack_expect.c
- net/netfilter/nf_conntrack_h323_main.c 2 additions, 1 deletionnet/netfilter/nf_conntrack_h323_main.c
- net/netfilter/nf_conntrack_netlink.c 10 additions, 10 deletionsnet/netfilter/nf_conntrack_netlink.c
Loading