<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>iptables | Devel</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/iptables/devel/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>13 Feb  2012 03:52:50 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | iptables | Devel</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/iptables/devel/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>Auto-responder test</title>
<description>Please ignore</description>
<pubDate>20 Sep  2007 03:55:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69120</link>
</item><item>
<title>Old lists are disabled as of now</title>
<description>gmane has picked up the new lists, marc.info probably also (if not it will soon), so effective immediately, I&amp;#039;m disabling subscriptions and postings t</description>
<pubDate>20 Sep  2007 03:51:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69121</link>
</item><item>
<title>The cause of NAT/Masquerading not perfomed</title>
<description>Hey everyone, What can be attributed as the cause for the problem of not performing an NAT/Masquerade? This is a basic scenario where a computer on t</description>
<pubDate>19 Sep  2007 07:05:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69112</link>
</item><item>
<title>FYI: Solved a dynamic linking loader issues with iptables,libiptc</title>
<description>Hi, Jseper: I have a problem which you have solved. Error:Couldn&amp;#039;t load target &amp;#039;standard&amp;#039;: /lib/iptc/iptables/libipt_standard.so:undefined symbol: r</description>
<pubDate>19 Sep  2007 00:51:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69113</link>
</item><item>
<title>Question : multicast through NAT server using iptables.</title>
<description>I have some quesions about address multicasting through NAT server using iptables.  1 Does NAT server allow address multicasting ? 2 if does allow,</description>
<pubDate>19 Sep  2007 00:43:56 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69115</link>
</item><item>
<title>[REMINDER]: netfilter list moved to kernel.org</title>
<description>Just a reminder, the netfilter and netfilter-devel lists have moved to kernel.org, you can subscribe to the new lists at http://vger.kernel.org/vger-</description>
<pubDate>18 Sep  2007 04:35:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69102</link>
</item><item>
<title>BUGs at tcp state transition?</title>
<description>Hi, all.  When I tested 2.6.20.16, found something strange. The following is the test case: 1. Establish a connection between client and server [.C</description>
<pubDate>17 Sep  2007 18:43:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69094</link>
</item><item>
<title>Re: [PATCH] Suppress usage of lastnlh as it was overwritting last packet of the message.</title>
<description>Eric Leblond wrote: &amp;gt; Hello, &amp;gt; &amp;gt; The following patch fixes the handling of netlink packets containing &amp;gt; multiple messages. &amp;gt; &amp;gt; As exposed during net</description>
<pubDate>17 Sep  2007 06:41:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69089</link>
</item><item>
<title>Netfilter List cross-subscription [Re: Test]</title>
<description>Patrick McHardy wrote: &amp;gt; netfilter-devel cross-subscription test, please ignore  The cross-subscription appears to work, unfortunately (due to the su</description>
<pubDate>17 Sep  2007 04:47:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69075</link>
</item><item>
<title>libnfconntrack and ipv6 addresses</title>
<description>Hi, I am developping an application that uses libnfconntrack. I currently try to get the ipv6 addresses from a conntrack. However it seems it is no</description>
<pubDate>17 Sep  2007 00:58:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69074</link>
</item><item>
<title>xt_time 20070915 (iptables)</title>
<description>libipt_time from POM-ng, augmented by:  * day-of-month support (for example &amp;quot;match on the 15th of each month&amp;quot;) * inversion support for --weekdays an</description>
<pubDate>15 Sep  2007 10:41:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69065</link>
</item><item>
<title>xt_time 20070915</title>
<description>For 2.6.24. Please comment, thanks!  ===  ipt_time from POM-ng augmented by:  * xtables * ipv6 support * day-of-month support (for example &amp;quot;match</description>
<pubDate>15 Sep  2007 09:07:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69059</link>
</item><item>
<title>Re: netfilter workshop group photo annotations</title>
<description>Harald Welte wrote: &amp;gt; I don&amp;#039;t have an annotated photo, but maybe somebody wants to make one &amp;gt; using the following data: &amp;gt; &amp;gt; (all from left to right)</description>
<pubDate>15 Sep  2007 03:40:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69052</link>
</item><item>
<title>netfilter.org debian migration (was Re: test)</title>
<description>On Thu, Sep 13, 2007 at 07:09:21PM +0200, Jan Engelhardt wrote: &amp;gt; &amp;gt; On Sep 13 2007 18:42, Harald Welte wrote: &amp;gt; &amp;gt; &amp;gt; &amp;gt;testing the new debian based lis</description>
<pubDate>15 Sep  2007 03:04:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69053</link>
</item><item>
<title>netfilter workshop group photo annotations</title>
<description>On Wed, Sep 12, 2007 at 08:30:48PM +0200, Jan Engelhardt wrote: &amp;gt; &amp;gt; On Sep 12 2007 12:36, Patrick McHardy wrote: &amp;gt; &amp;gt; The netfilter and netfilter-deve</description>
<pubDate>15 Sep  2007 02:37:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69055</link>
</item><item>
<title>test</title>
<description>testing the new debian based list setup -- - Harald Welte &amp;lt;laforge@netfilter.org&amp;gt;         http://netfilter.org/ ============================</description>
<pubDate>13 Sep  2007 09:42:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69050</link>
</item><item>
<title>[PATCH] add support to related connections via ctnetlink</title>
<description>This patch adds support to relate a connection to an existing master connection. This patch is used by conntrackd to correctly replicate related conne</description>
<pubDate>13 Sep  2007 08:47:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69047</link>
</item><item>
<title>is skb payload missing when using NF_IP_POST_ROUTING ?</title>
<description>Hi, I&amp;#039;m trying to develop a queue handler using netfilter and iptables mangling to catch all data coming in and out of my network card. I&amp;#039;m using a h</description>
<pubDate>13 Sep  2007 06:20:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69077</link>
</item><item>
<title>[ADMINISTRATIVE] netfilter.org downtime</title>
<description>Hi! There will be an administrative downtime of pracitcally all netfilter.org services during the next couple of days (thursday/friday). I don&amp;#039;t real</description>
<pubDate>12 Sep  2007 08:37:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69036</link>
</item><item>
<title>Re: [NETLINK]: Introduce nested and byteorder flag to netlink attribute</title>
<description>From: Thomas Graf &amp;lt;tgraf@suug.ch&amp;gt; Date: Wed, 12 Sep 2007 14:41:45 +0200 &amp;gt; This change allows the generic attribute interface to be used within &amp;gt; the</description>
<pubDate>12 Sep  2007 05:45:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69031</link>
</item><item>
<title>[NETLINK]: Introduce nested and byteorder flag to netlink attribute</title>
<description>This change allows the generic attribute interface to be used within the netfilter subsystem where this flag was initially introduced. The byte-order</description>
<pubDate>12 Sep  2007 05:41:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69032</link>
</item><item>
<title>[ANNOUNCE]: netfilter-devel and netfilter list moving to kernel.org</title>
<description>The netfilter and netfilter-devel mailinglists are moving to kernel.org, you can subscribe to the new lists at: http://vger.kernel.org/vger-lists.htm</description>
<pubDate>12 Sep  2007 03:36:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69029</link>
</item><item>
<title>Re: u32 extension</title>
<description>On Sep 10 2007 11:18, Patrick McHardy wrote: &amp;gt;Hi Jan, &amp;gt; &amp;gt;I just noticed the u32 extension is missing from iptables. &amp;gt;Could you send me your latest ver</description>
<pubDate>10 Sep  2007 03:28:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69011</link>
</item><item>
<title>[NETFILTER 02/02]: Fix/improve deadlock condition on module removal netfilter</title>
<description>[NETFILTER]: Fix/improve deadlock condition on module removal netfilter So I&amp;#039;ve had a deadlock reported to me. I&amp;#039;ve found that the sequence of event</description>
<pubDate>09 Sep  2007 15:20:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69010</link>
</item><item>
<title>[NETFILTER 01/02]: nf_conntrack_ipv4: fix &amp;quot;Frag of proto ...&amp;quot; messages</title>
<description>[NETFILTER]: nf_conntrack_ipv4: fix &amp;quot;Frag of proto ...&amp;quot; messages Since we&amp;#039;re now using a generic tuple decoding function in ICMP connection tracking,</description>
<pubDate>09 Sep  2007 15:20:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69009</link>
</item><item>
<title>[NETFILTER 00/02]: Netfilter fixes</title>
<description>Hi Dave, these patches fix an incorrect warning message in IPv4 connection tracking and the module unload deadlock notices by Neil Horman. Please ap</description>
<pubDate>09 Sep  2007 15:20:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/69008</link>
</item><item>
<title>[RFC] iptables namespaces</title>
<description>Hi again, I&amp;#039;ve been thinking about some kind of namespaces in iptables where one can switch from one set of rules to another set of rules by flickin</description>
<pubDate>07 Sep  2007 11:02:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68990</link>
</item><item>
<title>[RFC] High Performance Packet Classification (HPPC) to succeed HIPAC</title>
<description>Hi, I&amp;#039;m a user of nf-HIPAC (http://www.hipac.org) and I&amp;#039;ve tried to monitor it&amp;#039;s progress into the main kernel tree. Unfortunately, the work on nf-HI</description>
<pubDate>07 Sep  2007 02:09:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68987</link>
</item><item>
<title>Re: [PATCH 2/2] Fix (improve) deadlock condition on module removal netfilter socket option removal</title>
<description>On Wed, 2007-09-05 at 16:26 -0400, Jon Masters wrote: &amp;gt; On Tue, 2007-09-04 at 16:30 -0400, Neil Horman wrote: &amp;gt; &amp;gt; &amp;gt;   2nd of two patches. This pat</description>
<pubDate>05 Sep  2007 15:41:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68957</link>
</item><item>
<title>Reading traffic from a serial port</title>
<description>Hello, I need to see a traffic flowing between two nodes over a serial port /dev/ttyS0. The log files show me that the traffic exchange is going on an</description>
<pubDate>05 Sep  2007 08:30:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68950</link>
</item><item>
<title>Re: [PATCH 0/2] Fix (improve) deadlock condition on module removal netfilter socket option removal</title>
<description>Neil Horman wrote: &amp;gt; Hey all- &amp;gt;    So I&amp;#039;ve had a deadlock reported to me. I&amp;#039;ve found that the sequence of &amp;gt; events goes like this: &amp;gt; &amp;gt; 1) process</description>
<pubDate>05 Sep  2007 08:22:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68949</link>
</item><item>
<title>ipporthash doesn&amp;#039;t work ( ipset-2.3.0, iptables-1.3.8-15, kernel-2.6.22.3-7-bigsmp, SuSE 10.3 Beta2)</title>
<description>Hi,  I compiled and installed ipset-2.3.0, I found the iphash worked fine but ipporthash acted wired. Here&amp;#039;s the scenario:  suse10-3:~ # ipset -N s</description>
<pubDate>04 Sep  2007 15:16:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68943</link>
</item><item>
<title>[PATCH 2/2] Fix (improve) deadlock condition on module removal netfilter socket option removal</title>
<description>Hey-     2nd of two patches. This patch enhances modprobe to operate like rmmod in non-blocking mode. It also adds a -w option to allow for expl</description>
<pubDate>04 Sep  2007 13:30:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68961</link>
</item><item>
<title>[PATCH 1/2] Fix (improve) deadlock condition on module removal netfilter socket option removal</title>
<description>Patch 1/2 to fix netfilter socket option removal This patch changes netfilter socket options to do reference counting on the module refcounter (And s</description>
<pubDate>04 Sep  2007 13:27:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68960</link>
</item><item>
<title>[PATCH 0/2] Fix (improve) deadlock condition on module removal netfilter socket option removal</title>
<description>Hey all-     So I&amp;#039;ve had a deadlock reported to me. I&amp;#039;ve found that the sequence of events goes like this: 1) process A (modprobe) runs to remov</description>
<pubDate>04 Sep  2007 13:24:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68959</link>
</item><item>
<title>[iptables] NFLOG-testx is not executable</title>
<description>Hi, The test for NFLOG is not executable. This prevents NFLOG from building. A commiter should run the following command to change executable proper</description>
<pubDate>04 Sep  2007 12:37:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68940</link>
</item><item>
<title>[PATCH] Makefile for man pages of xtables extensions</title>
<description>Hello, I made this patch to include all available matches and targets to iptables.8 and ip6tables.8 man pages. The source file is lixt_*.c but the ma</description>
<pubDate>03 Sep  2007 05:48:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68929</link>
</item><item>
<title>Measure CPU load of a filter application based on libipq</title>
<description>Hi all, I&amp;#039;m on a Fedora Core 6 i386 machine. I have implemented a packet filter based on libipq which works great. It basically looks into the IP and</description>
<pubDate>03 Sep  2007 01:15:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68916</link>
</item><item>
<title>[PATCH 3/3] libnl: add netfilter log support</title>
<description></description>
<pubDate>02 Sep  2007 22:12:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68914</link>
</item><item>
<title>[PATCH 2/3] libnl: add netfilter conntrack support</title>
<description></description>
<pubDate>02 Sep  2007 22:11:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68913</link>
</item><item>
<title>[PATCH 1/3] libnl: add netfilter support</title>
<description></description>
<pubDate>02 Sep  2007 22:11:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68912</link>
</item><item>
<title>netfilter support in libnl</title>
<description>There have been comments in the past on this list about using libnl for the netfilter netlink support, and since I would like to use a common library</description>
<pubDate>02 Sep  2007 22:09:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68911</link>
</item><item>
<title>hashlimit match : how is that to use hop count as the hash info?</title>
<description>Hi, Is it possible to use hop count (TTL) as the hash value? I can’t find the way to defend against spoofing based DDoS attacks. If the hop count</description>
<pubDate>31 Aug  2007 23:16:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68886</link>
</item><item>
<title>Re: ipv4_get_l4proto: Frag of proto 17</title>
<description>Meelis Roos wrote: &amp;gt; Yesterdays git snapsot on a normal home PC spams dmesg with the &amp;gt; following line: &amp;gt; ipv4_get_l4proto: Frag of proto 17  In what</description>
<pubDate>30 Aug  2007 00:08:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68856</link>
</item><item>
<title>[NETFILTER]: xt_tcpudp: fix wrong struct in udp_checkentry</title>
<description>Hi Dave, the attached patch fixes an incorrectly used structure in xt_tcpudp, which apparently causes problems on CRIS. Please apply, thanks.</description>
<pubDate>30 Aug  2007 00:04:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68855</link>
</item><item>
<title>Re: ipset patch-o-matic-ng-20070524.tar.bz2 doesn&amp;#039;t work on SuSE 10.3	Beta2 kernel (2.6.22.3-7-bigsmp)</title>
<description>Hung Lin wrote: &amp;gt; Hi, &amp;gt; &amp;gt; I tried to use ipset patch-o-matic-ng to patch SuSE 10.3 Beta2 kernel but it doesn&amp;#039;t work. Here&amp;#039;s the commands I run: &amp;gt; &amp;gt;</description>
<pubDate>29 Aug  2007 09:59:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68838</link>
</item><item>
<title>Re: looking up a flow in the kernel structures given its identifier</title>
<description>Em Tue, Aug 28, 2007 at 11:48:55PM +0200, Sirine Chaitou escreveu: &amp;gt; Thanks a lot for your help. &amp;gt; Well, my purpose is to overwrite the initial sequen</description>
<pubDate>29 Aug  2007 03:59:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68814</link>
</item><item>
<title>Re: Crash report 2.6.22.5</title>
<description>Hi Pete, On 28/08/07, Pete Monroe &amp;lt;pizzlemonrizzle@gmail.com&amp;gt; wrote: &amp;gt; Hi, &amp;gt; &amp;gt; Sorry there&amp;#039;s not more to go on here. &amp;gt; &amp;gt; A 32-bit firewall running th</description>
<pubDate>28 Aug  2007 16:51:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68835</link>
</item><item>
<title>Very urgent: using network kernel header files from our own module</title>
<description>Dear all, Can anyone tell me how can I call functions in the kernel sources header files from a different module? I explain: I am interested in using</description>
<pubDate>28 Aug  2007 15:25:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68808</link>
</item><item>
<title>Very urgent: looking up a flow in the kernel structures given its identifier</title>
<description>Hello, I am looking for a function which, supplied whith the tuple identifier (ip_src,ip_dst,p_src,p_dst), returns the corresponding skb. Does this</description>
<pubDate>28 Aug  2007 12:21:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68806</link>
</item><item>
<title>[ANNOUNCE] ipset 2.3.0 released</title>
<description>Hi, I&amp;#039;m happy to announce the new ipset release. The main changes are  - jiffies rollover bug in iptree type fixed (reported by Lukasz Nierycho</description>
<pubDate>28 Aug  2007 04:05:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68800</link>
</item><item>
<title>ipset patch-o-matic-ng-20070524.tar.bz2 doesn&amp;#039;t work on SuSE 10.3 Beta2 kernel (2.6.22.3-7-bigsmp)</title>
<description>Hi, I tried to use ipset patch-o-matic-ng to patch SuSE 10.3 Beta2 kernel but it doesn&amp;#039;t work. Here&amp;#039;s the commands I run: suse10-3:/usr/src/patch-o</description>
<pubDate>27 Aug  2007 14:33:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68797</link>
</item><item>
<title>new target: -j TEE</title>
<description>Hi @ all, The ROUTE targe seems to be finaly gone from pom-ng and we need a solution for the --tee function. So I deciced to use some parts from the</description>
<pubDate>27 Aug  2007 05:08:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68781</link>
</item><item>
<title>[PATCH] Last vestiges of NFC</title>
<description>Hello! It appears that the tweaking of NFC_* bits of nfcache was almost completely done away with around the times of these threads: http://lists.ne</description>
<pubDate>25 Aug  2007 10:21:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68754</link>
</item><item>
<title>ipt_ACCOUNT 1.11 released</title>
<description>Hello, I&amp;#039;m pleased to announce the release of ipt_ACCOUNT 1.11. Changelog: - Workaround for kernel bug when using one GB RAM and more This release</description>
<pubDate>24 Aug  2007 05:34:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68749</link>
</item><item>
<title>[PATCH] netfilter: xt_tcpudp.c: wrong struct in udp_checkentry</title>
<description>I found what looks like a copy-paste error in udp_checkentry, see patch below. It doesn&amp;#039;t seem to have any effect on the x86 architecture but it does</description>
<pubDate>24 Aug  2007 04:50:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68833</link>
</item><item>
<title>/proc/net/ip_conntrack trange behavior</title>
<description>Hi, all     When I checked /proc/net/ip_conntrack in my Linux server, I found some strange tracks like the following: [normal case] tcp   6 3</description>
<pubDate>24 Aug  2007 00:43:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68745</link>
</item><item>
<title>netfilter hook does not see some packets ...</title>
<description>I have a situation where my kernel module that registers the nf hooks does does not see some packets. Those packets seems to be those that are REDIREC</description>
<pubDate>23 Aug  2007 05:23:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68731</link>
</item><item>
<title>The &amp;quot;value&amp;quot; of &amp;quot;-m dscp -dscp&amp;quot; for iptables command</title>
<description>Hello,   I find a bug in the manpage of iptables:   The description for the value in option &amp;quot;-m dscp -dscp&amp;quot; should be modified to 0~63.   The</description>
<pubDate>22 Aug  2007 22:17:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68730</link>
</item><item>
<title>conntrack: Connection close event?</title>
<description>Hi, this is my first request. I checked google, nf-faqs and conntrack-homepage without sufficient results for this problem: In Short: I need to kno</description>
<pubDate>22 Aug  2007 11:01:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68724</link>
</item><item>
<title>Sharing information for many rules using same module</title>
<description>Hi. I am working on simple netfilter match extension. It takes packet, analyzes it, and puts all info in structure. Then it looks at fields in matchin</description>
<pubDate>21 Aug  2007 07:54:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68712</link>
</item><item>
<title>How to use the tcp_info structure in linux/tcp.h</title>
<description>Dear All, I am looking to: 1. how to tell linux to look exactly to the flags of a TCP header (struct tcphdr * tcp_hdr; ... I want to access the tcp_hd</description>
<pubDate>21 Aug  2007 00:32:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68707</link>
</item><item>
<title>[RFC] ipset: New set type iptreemap, userspace part</title>
<description>Makefile     |  2 -  ipset_iptreemap.c | 209 +++++++++++++++++++++++++++++++++++++++++++++++++++++  2 files changed, 210 insertions(+), 1 de</description>
<pubDate>20 Aug  2007 13:37:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68698</link>
</item><item>
<title>[RFC] ipset: New set type iptreemap, kernel part</title>
<description>include/linux/netfilter_ipv4/ip_set_iptreemap.h |  40 +  net/ipv4/netfilter/Kconfig           |  8  net/ipv4/netfilter/Makefile</description>
<pubDate>20 Aug  2007 13:36:56 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68700</link>
</item><item>
<title>[RFC] ipset: New set type iptreemap</title>
<description>Hi all, based on the feedback from Jan Engelhardt I&amp;#039;ve converted the fullipmap [1] set type I announced last week to manage the bitmaps with a tree</description>
<pubDate>20 Aug  2007 13:36:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68699</link>
</item><item>
<title>xt_time 20070820 (iptables)</title>
<description>iptables part. --- extensions/.time-testx   |  2  extensions/libxt_time.man |  16 + extensions/libxt_time.c  | 497 ++++++++++++++++++++++</description>
<pubDate>20 Aug  2007 12:20:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68691</link>
</item><item>
<title>xt_time 20070820</title>
<description>Hi,  this is xt_time, posted for reference and discussion. Not perfect yet, but a start. &amp;lt;&amp;lt;&amp;lt; ipt_time from POM-ng augmented by:  * xtables * ipv</description>
<pubDate>20 Aug  2007 12:19:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68690</link>
</item><item>
<title>Kernel oops during netfilter memory allocation</title>
<description>Hey there, I&amp;#039;m currently debugging a kernel oops with kernel 2.6.21.7 that occurs from time to time with our netfilter accounting module ipt_ACCOUNT</description>
<pubDate>20 Aug  2007 09:08:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68688</link>
</item><item>
<title>A question about the skbuff handling - Thanks for your answer.</title>
<description>Dear all, First of all, I would like to say that I got troubles when sending to the Netfilter-devel mailing list, that&amp;#039;s why I am sending my request a</description>
<pubDate>20 Aug  2007 08:32:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68687</link>
</item><item>
<title>Memory allocation inside target handler</title>
<description>Hi there, I&amp;#039;m currently debugging a memory allocation issue in ipt_ACCOUNT running on 2.6.21.7. The module allocates memory using get_zeroed_page(GF</description>
<pubDate>17 Aug  2007 08:17:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68655</link>
</item><item>
<title>Old ip6t_REJECT.h header file in iptables include dir</title>
<description>Hello! Apologies if this is a bad place to report bugs/fixes, but bugzilla.netfilter.org appears to be down for some time now... I noticed some inco</description>
<pubDate>17 Aug  2007 01:55:17 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68643</link>
</item><item>
<title>revisit: ipset nethash set type limited to /31</title>
<description>Hi, (Original post on netfilter@lists.netfilter.org: https://lists.netfilter.org/pipermail/netfilter/2007-August/069497.html) My employer has an in</description>
<pubDate>16 Aug  2007 23:54:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68642</link>
</item><item>
<title>Locking issue</title>
<description>Hi there, This email is regarding ebtables code i.e. bridge level filtering framework of netfilter. I have sent this email to ebtables mailing list a</description>
<pubDate>16 Aug  2007 10:54:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68635</link>
</item><item>
<title>[PATCH 6/6] netfilter: xt_u32: fix length checks in u32_match_it</title>
<description>It seems an extraneous trailing &amp;#039;;&amp;#039; has slipped into the skb length checks in u32_match_it() triggering an unconditional missmatch. Signed-off-by: An</description>
<pubDate>16 Aug  2007 06:19:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68628</link>
</item><item>
<title>[RFC] [PATCH] ipset: New set type fullipmap, userspace part</title>
<description>--- /dev/null +++ b/ipset_fullipmap.c @@ -0,0 +1,202 @@ +/* Copyright 2007 Sven Wegener &amp;lt;sven.wegener@stealer.net&amp;gt; + * + * This program is free softwa</description>
<pubDate>16 Aug  2007 00:22:25 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68625</link>
</item><item>
<title>[RFC] [PATCH] ipset: New set type fullipmap, kernel part</title>
<description>--- /dev/null +++ b/include/linux/netfilter_ipv4/ip_set_fullipmap.h @@ -0,0 +1,24 @@ +#ifndef __IP_SET_FULLIPMAP_H +#define __IP_SET_FULLIPMAP_H + +#i</description>
<pubDate>16 Aug  2007 00:22:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68626</link>
</item><item>
<title>[RFC] [PATCH] ipset: New set type fullipmap</title>
<description>Hi, I&amp;#039;d like to get your initial feedback on a new set type called fullipmap. The fullipmap type uses dynamically allocated bitmaps to represent eve</description>
<pubDate>16 Aug  2007 00:22:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68624</link>
</item><item>
<title>Re: drivers/infiniband/mlx/mad.c misplaced ;</title>
<description>On Wed, 2007-08-15 at 19:58 -0400, Dave Jones wrote: &amp;gt; Signed-off-by: Dave Jones &amp;lt;davej@redhat.com&amp;gt; &amp;gt; &amp;gt; diff --git a/drivers/infiniband/hw/mlx4/mad.c</description>
<pubDate>15 Aug  2007 17:40:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68621</link>
</item><item>
<title>patch/ipset: fix typo in ipset error msg: &amp;quot;Range to large. Max is %d IPs in range\n&amp;quot;</title>
<description>Hi Pablo &amp;amp; others, Here is a super minor patch. Request for clemency in advance if there is a better way to submitting such tiny patches... a branch</description>
<pubDate>14 Aug  2007 20:53:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68616</link>
</item><item>
<title>[NETFILTER 04/04]: nf_nat_sip: don&amp;#039;t drop short packets</title>
<description>[NETFILTER]: nf_nat_sip: don&amp;#039;t drop short packets Don&amp;#039;t drop packets shorter than &amp;quot;SIP/2.0&amp;quot;, just ignore them. Keep-alives can validly be shorter for</description>
<pubDate>14 Aug  2007 09:40:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68603</link>
</item><item>
<title>[NETFILTER 03/04]: nf_conntrack_sip: fix SIP-URI parsing</title>
<description>[NETFILTER]: nf_conntrack_sip: fix SIP-URI parsing The userinfo component of a SIP-URI is optional, continue parsing at the beginning of the SIP-URI</description>
<pubDate>14 Aug  2007 09:40:17 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68602</link>
</item><item>
<title>[NETFILTER 02/04]: nf_conntrack_sip: check sname != NULL before calling strncmp</title>
<description>[NETFILTER]: nf_conntrack_sip: check sname != NULL before calling strncmp The check got lost during the conversion to nf_conntrack. Signed-off-by: P</description>
<pubDate>14 Aug  2007 09:40:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68601</link>
</item><item>
<title>[NETFILTER 01/04]: netfilter: xt_u32 bug correction</title>
<description>[NETFILTER]: netfilter: xt_u32 bug correction An extraneous &amp;quot;;&amp;quot; makes xt_u32 match useless Signed-off-by: Eric Dumazet &amp;lt;dada1@cosmosbay.com&amp;gt; Signed-</description>
<pubDate>14 Aug  2007 09:40:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68600</link>
</item><item>
<title>[NETFILTER 00/04]: Netfilter fixes</title>
<description>Hi Dave, these patches fix an extraneous &amp;quot;;&amp;quot; in the new u32 match and three minor bugs in the SIP conntrack helper. Please apply, thanks.  net/ipv4</description>
<pubDate>14 Aug  2007 09:40:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68599</link>
</item><item>
<title>[PATCH] libnetfilter_conntrack: Add getter/setter for ids.</title>
<description></description>
<pubDate>14 Aug  2007 00:20:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68585</link>
</item><item>
<title>[PATCH] libnetfilter_conntrack: Packet/byte counters are 64 bit</title>
<description></description>
<pubDate>14 Aug  2007 00:19:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68584</link>
</item><item>
<title>[PATCH] libnetfilter_conntrack: Fix getters for big-endian</title>
<description></description>
<pubDate>14 Aug  2007 00:18:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68583</link>
</item><item>
<title>[PATCH][CTNETLINK] Include the id in conntrack netlink events.</title>
<description>I need the id in ctnetlink events for my application, so here&amp;#039;s a patch to add it in case this wasn&amp;#039;t left out intentionally.</description>
<pubDate>13 Aug  2007 22:07:56 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68578</link>
</item><item>
<title>rule limitations?</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 For relatively obscure reasons, I am trying to build a set of rules that run into the hundreds of thous</description>
<pubDate>13 Aug  2007 16:48:06 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68615</link>
</item><item>
<title>[PATCH] [334/2many] MAINTAINERS - NETFILTER/IPTABLES/IPCHAINS</title>
<description>Add file pattern to MAINTAINER entry Signed-off-by: Joe Perches &amp;lt;joe@perches.com&amp;gt; diff --git a/MAINTAINERS b/MAINTAINERS index 7e3b438..bc571b8 1006</description>
<pubDate>12 Aug  2007 23:32:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68576</link>
</item><item>
<title>[PATCH RFT] Improve iptables error reporting</title>
<description>Hi Here&amp;#039;s a small patch that reworks the iptables/ip6tables error reporting a bit. The purpose of this patch is to try to provide more resonable err</description>
<pubDate>11 Aug  2007 16:21:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68561</link>
</item><item>
<title>Kernel panic (destroy_conntrack) unloading nf_conntrack_ftp before</title>
<description>Hi all, that&amp;#039;s my first &amp;quot;bug report&amp;quot; here, so please feel free to kick my ass for whatever I&amp;#039;m doing wrong ;-) Yesterday I experienced a kernel pani</description>
<pubDate>10 Aug  2007 01:35:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68572</link>
</item><item>
<title>[PATCH] [LIBNFNETLINK] Fix endless loop on unknown netfilter attributes.</title>
<description>Hi! [LIBNFNETLINK] Fix endless loop on unknown netfilter attributes. This prevents an endless loop when nfnl_check_attributes() sees an unknown attr</description>
<pubDate>08 Aug  2007 12:59:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68538</link>
</item><item>
<title>[ANNOUNCE] Netfilter-related Linux kernel security updates</title>
<description>Hi! Nowadays, Linux Kernel related security issues are handled through the -stable series. Since the Netfilter project has part of his software in th</description>
<pubDate>08 Aug  2007 04:37:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68530</link>
</item><item>
<title>[PATCH] fix handling of netlink packets containing multiple messages</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  Hi,  I&amp;#039;ve found a bug in libnfnetlink which does not handle correctly netlink packets made of mor</description>
<pubDate>07 Aug  2007 23:08:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68526</link>
</item><item>
<title>[2.6.22.2 review 81/84] Netfilter: Fix logging regression</title>
<description>From: Patrick McHardy &amp;lt;kaber@trash.net&amp;gt; [NETFILTER]: Fix logging regression Loading one of the LOG target fails if a different target has already re</description>
<pubDate>07 Aug  2007 13:49:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68524</link>
</item><item>
<title>patch netfilter-fix-logging-regression.patch queued to -stable tree</title>
<description>This is a note to let you know that we have just queued up the patch titled    Subject: Netfilter: Fix logging regression to the 2.6.22-stable tre</description>
<pubDate>07 Aug  2007 11:43:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68523</link>
</item><item>
<title>patch nf_conntrack-don-t-track-locally-generated-special-icmp-error.patch queued to -stable tree</title>
<description>This is a note to let you know that we have just queued up the patch titled    Subject: nf_conntrack: don&amp;#039;t track locally generated special ICMP er</description>
<pubDate>07 Aug  2007 10:09:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68521</link>
</item><item>
<title>DNS rebinding</title>
<description>Hello List, There is an article about DNS rebinding at the following site: http://crypto.stanford.edu/dns/  &amp;quot;Circumvention-Resistant Firewalls. Fire</description>
<pubDate>07 Aug  2007 09:11:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68533</link>
</item><item>
<title>[ANNOUNCE] libnetfilter_queue release 0.0.15</title>
<description>Hi! The netfilter project presents libnetfilter_queue 0.0.15 libnetfilter_queue is a userspace library providing an API to packets that have been qu</description>
<pubDate>07 Aug  2007 07:20:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/iptables/devel/68520</link>
</item>
</channel>
</rss>

