Re: 2.6.12: connection tracking broken?
Herbert Xu <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.netfilter.devel,gmane.linux.kernel,gmane.linux.network.bridge.ebtables.devel |
|---|---|
| Organization | Core |
| Message-ID | <[email protected]> |
Patrick McHardy <[email protected]> wrote: > > The bridge-netfilter code defers calling of some NF_IP_* hooks to the > bridge layer, when the conntrack reference is already gone, so the entry Why does it defer them at all? Shouldn't the fact that the device is bridged be transparent to the IP layer? Cheers, -- Visit Openswan at http://www.openswan.org/ Email: Herbert Xu ~{PmV>HI~} <[email protected]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt