Re: 'ip route' and 'ipset'...

Anton Danilov <[email protected]> Fri, 31 Jan 2020 23:10:22 +0300
Newsgroups gmane.linux.network.routing
Message-ID <CAEzD07LVRdmfr8-qeZWOoqCLa3qX9Yb41iA7RvfZyDD=pRD-pA@mail.gmail.com>
Hello
If you want to reroute local traffic, you can match packets with ipset
and mark them in raw/OUTPUT table to change the route decision.

On Fri, 31 Jan 2020 at 19:36, Marco Gaiarin <[email protected]> wrote:
>
> Mandi! Phil Sutter
>   In chel di` si favelave...
>
> > Not to my knowledge,
>
> OK.
>
>
> > but you may use nftables' route type chains to
> > implement policy routing in nftables which supports sets natively. If
> > any of paket mark, source or destination address or TOS fields are
> > changed by a rule in route type chain, routing decision will be redone
> > for the packet.
>
> Aaahh... i've forgot to specify: it is 'local' traffic, so i've no
> 'PREROUTE' and 'POSTROUTE' to mark to...
>
> --
> dott. Marco Gaiarin                                     GNUPG Key ID: 240A3D66
>   Associazione ``La Nostra Famiglia''          http://www.lanostrafamiglia.it/
>   Polo FVG   -   Via della Bontà, 7 - 33078   -   San Vito al Tagliamento (PN)
>   marco.gaiarin(at)lanostrafamiglia.it   t +39-0434-842711   f +39-0434-842797
>
>                 Dona il 5 PER MILLE a LA NOSTRA FAMIGLIA!
>       http://www.lanostrafamiglia.it/index.php/it/sostienici/5x1000
>         (cf 00307430132, categoria ONLUS oppure RICERCA SANITARIA)



-- 
Anton Danilov.