include/uapi/linux/netfilter/xt_ipcomp.h
0 → 100644
+16
−0
+9
−0
+1
−0
net/netfilter/xt_ipcomp.c
0 → 100644
+111
−0
Loading
Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more
With this plugin, user could specify IPComp tagged with certain CPI that host not interested will be DROPped or any other action. For example: iptables -A INPUT -p 108 -m ipcomp --ipcompspi 0x87 -j DROP ip6tables -A INPUT -p 108 -m ipcomp --ipcompspi 0x87 -j DROP Then input IPComp packet with CPI equates 0x87 will not reach upper layer anymore. Signed-off-by:Fan Du <fan.du@windriver.com> Signed-off-by:
Pablo Neira Ayuso <pablo@netfilter.org>