NetFilter
[Top] [All Lists]

Re: netfilter_queue: how to obtain address info from queued packet

To: Michal Martinek <michal.martinek@siemens.com>
Subject: Re: netfilter_queue: how to obtain address info from queued packet
From: Gáspár Lajos <swifty@freemail.hu>
Date: Tue, 23 Jan 2007 11:27:45 +0100
Cc: netfilter@lists.netfilter.org
Delivered-to: sp-com-lists@consult.net
Delivered-to: netfilter-list1@securepoint.com
In-reply-to: <45B5E0DC.2020703@siemens.com>
List-archive: </pipermail/netfilter>
List-help: <mailto:netfilter-request@lists.netfilter.org?subject=help>
List-id: General discussion and user questions <netfilter.lists.netfilter.org>
List-post: <mailto:netfilter@lists.netfilter.org>
List-subscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=subscribe>
List-unsubscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=unsubscribe>
References: <45B5DD80.70809@siemens.com> <45B5DF09.6030001@freemail.hu> <45B5E0DC.2020703@siemens.com>
Sender: netfilter-bounces@lists.netfilter.org
User-agent: Thunderbird 1.5.0.9 (Windows/20061207)

Michal Martinek írta:


Gáspár Lajos wrote:

Michal Martinek írta:
Hello all,

I am quite a newbie to the netfilter world, so maybe my approach is naive. I would like to block communication coming from/to some ports according to the content of packets. Unfortunately these ports are not static, so port specific netfilter rule cannot be used. So my question is:

Do you know the STRING module ?

I'm afraid not. Can you give me some explanation (or link)?
Well... :) man iptables...
iptables -A FORWARD -j DROP -p tcp -m string --string 'Some string' --algo kmp

Is it possible to obtain some address info (source/destination address and ports) from the packet queued from netfilter?





<Prev in Thread] Current Thread [Next in Thread>