netfilter: add IPv4/6 IPComp extension match support
With this plugin, user could specify IPComp tagged with certain CPI that host not interested will be DROPped or any other action. For example: iptables -A INPUT -p 108 -m ipcomp --ipcompspi 0x87 -j DROP ip6tables -A INPUT -p 108 -m ipcomp --ipcompspi 0x87 -j DROP Then input IPComp packet with CPI equates 0x87 will not reach upper layer anymore. Signed-off-by:Fan Du <fan.du@windriver.com> Signed-off-by:
Pablo Neira Ayuso <pablo@netfilter.org>
Showing
- include/uapi/linux/netfilter/Kbuild 1 addition, 0 deletionsinclude/uapi/linux/netfilter/Kbuild
- include/uapi/linux/netfilter/xt_ipcomp.h 16 additions, 0 deletionsinclude/uapi/linux/netfilter/xt_ipcomp.h
- net/netfilter/Kconfig 9 additions, 0 deletionsnet/netfilter/Kconfig
- net/netfilter/Makefile 1 addition, 0 deletionsnet/netfilter/Makefile
- net/netfilter/xt_ipcomp.c 111 additions, 0 deletionsnet/netfilter/xt_ipcomp.c
include/uapi/linux/netfilter/xt_ipcomp.h
0 → 100644
net/netfilter/xt_ipcomp.c
0 → 100644
Please register or sign in to comment