Re: Warning: never matched protocol: ah. use extension match instead. | |
| [Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] | |
Thomas Jacob wrote:
Could someone clarify what exactly the warning message in the subject (from ip6tables) is supposed to tell me? It looks like that ip6tables -p ah (or -p in general) would match packets that contain an ah header as the last extension header whereas -m ah matches packets that contain an ah header at any position, but I'm not sure.
Almost. "-p" uses the first non-extension header (which can never be AH), while "-m ah" matches on AH extension headers.
The core of the question is this: how does one pass unspecified ipsec traffic in ip6tables (the way you could do with -p ah + -p esp in iptables)?
"-m ah" and both "-m esp" and "-p esp" should work. -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html
[Linux Netfilter Development] [Linux Kernel Development] [TCP/IP Books] [Linux Resources] [LARTC] [Home] [Bugtraq] [Consulting] [Free Internet Dating] [Yosemite Forum] [Photo]