Re: IP Fragments
François-Xavier Le Bail <[email protected]>
| Newsgroups | gmane.linux.network.bridge.ebtables.user |
|---|---|
| Message-ID | <[email protected]> |
Hello Bart, Thank you for your answer. In ebt_ip.c, in case of match test on UDP or TCP source or destination port, do you think we need a test on the IP header to see if this is a IP fragment or not, because, in case of fragment, data in place of UDP/TCP Header (on 4 first bytes) could match the source or destination port ? Thank you, François-Xavier Bart De Schuymer a écrit : > Op zo, 08-01-2006 te 21:54 +0100, schreef François-Xavier Le Bail: > > Hello All, > > > > I would like to know how IP fragments are treated by ebtables. > > Treatment of IP fragments is determined by iptables connection tracking. > When iptables connection tracking is enabled, ebtables sees the > defragmented packets, else it sees the IP fragments. The brouting chain > and the bridge-nf-call-iptables option are special cases. See > > http://ebtables.sourceforge.net/brnf-faq.html > http://ebtables.sourceforge.net/ebtables-faq.html > _______________________________________________ > Ebtables-user mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/ebtables-user -- François-Xavier ------------------------------------------------------- This SF.net email is sponsored by: Splunk Inc. Do you grep through log files for problems? Stop! Download the new AJAX search engine that makes searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! http://ads.osdn.com/?ad_idv37&alloc_id865&op=click