netfilter: ipset: Exceptions support added to hash:*net* types
The "nomatch" keyword and option is added to the hash:*net* types,
by which one can add exception entries to sets. Example:
        ipset create test hash:net
        ipset add test 192.168.0/24
        ipset add test 192.168.0/30 nomatch
In this case the IP addresses from 192.168.0/24 except 192.168.0/30
match the elements of the set.
Signed-off-by:  Jozsef Kadlecsik <kadlec@blackhole.kfki.hu>
Signed-off-by:
Jozsef Kadlecsik <kadlec@blackhole.kfki.hu>
Signed-off-by:  Pablo Neira Ayuso <pablo@netfilter.org>
Pablo Neira Ayuso <pablo@netfilter.org>
Loading
Please register or sign in to comment
