Google
  Web www.spinics.net

Re: Warning: never matched protocol: ah. use extension match instead.

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]


Thomas Jacob wrote:
Could someone clarify what exactly the warning message in the subject
(from ip6tables) is supposed to tell me?

It looks like that ip6tables -p ah (or -p in general) would match
packets that contain an ah header as the last extension header whereas
-m ah matches packets that contain an ah header at any position, but
I'm not sure.

Almost. "-p" uses the first non-extension header (which can never
be AH), while "-m ah" matches on AH extension headers.

The core of the question is this: how does one pass unspecified
ipsec traffic in ip6tables (the way you could do with -p ah + -p esp in
iptables)?

"-m ah" and both "-m esp" and "-p esp" should work.
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html

[Linux Netfilter Development]     [Linux Kernel Development]     [TCP/IP Books]     [Linux Resources]     [LARTC]     [Home]     [Bugtraq]     [Consulting]     [Free Internet Dating]     [Yosemite Forum]     [Photo]

Powered by Linux