Re: IP Fragments

François-Xavier Le Bail <[email protected]>
Newsgroups gmane.linux.network.bridge.ebtables.user
Message-ID <[email protected]>
Hello Bart,

Thank you for your answer.

In ebt_ip.c, in case of match test on UDP or TCP source or destination port, do
you think we need a test on the IP header to see if this is a IP fragment or
not, because, in case of fragment, data in place of UDP/TCP Header (on 4 first
bytes) could match the source or destination port ?

Thank you,
François-Xavier

Bart De Schuymer a écrit :

> Op zo, 08-01-2006 te 21:54 +0100, schreef François-Xavier Le Bail:
> > Hello All,
> >
> > I would like to know how IP fragments are treated by ebtables.
>
> Treatment of IP fragments is determined by iptables connection tracking.
> When iptables connection tracking is enabled, ebtables sees the
> defragmented packets, else it sees the IP fragments. The brouting chain
> and the bridge-nf-call-iptables option are special cases. See
>
> http://ebtables.sourceforge.net/brnf-faq.html
> http://ebtables.sourceforge.net/ebtables-faq.html
> _______________________________________________
> Ebtables-user mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/ebtables-user

--
François-Xavier





-------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc. Do you grep through log files
for problems?  Stop!  Download the new AJAX search engine that makes
searching your log files as easy as surfing the  web.  DOWNLOAD SPLUNK!
http://ads.osdn.com/?ad_idv37&alloc_id865&op=click
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.