NetFilter
[Top] [All Lists]

Re: -s THIS ? (address belongs to one of of interfaces of local machine)

To: Yakov Lerner <iler.ml@gmail.com>
Subject: Re: -s THIS ? (address belongs to one of of interfaces of local machine) ?
From: Cedric Blancher <blancher@cartel-securite.fr>
Date: Thu, 22 Feb 2007 13:25:00 +0100
Cc: netfilter@lists.netfilter.org
Delivered-to: sp-com-lists@consult.net
Delivered-to: netfilter-list1@securepoint.com
In-reply-to: <f36b08ee0702210408h5db5027bmb1105d0d7d74cb17@mail.gmail.com>
List-archive: </pipermail/netfilter>
List-help: <mailto:netfilter-request@lists.netfilter.org?subject=help>
List-id: General discussion and user questions <netfilter.lists.netfilter.org>
List-post: <mailto:netfilter@lists.netfilter.org>
List-subscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=subscribe>
List-unsubscribe: <https://lists.netfilter.org/mailman/listinfo/netfilter>, <mailto:netfilter-request@lists.netfilter.org?subject=unsubscribe>
Organization: Cartel Securite
References: <f36b08ee0702210408h5db5027bmb1105d0d7d74cb17@mail.gmail.com>
Sender: netfilter-bounces@lists.netfilter.org
Le mercredi 21 février 2007 à 07:08 -0500, Yakov Lerner a écrit :
> Is there an easy way to specify '-s LOCAL', meaning
> not 127.0.0.1, but meaning that address matches any of
> addresses of interfaces belonging this this machine ?

All locally generated packets cna be filtered in OUTPUT chain, nowhere
else. That's a pretty convenient way to spot them. The same idea goes to
packets destined to local addresses, that end in INPUT chain, nowhere
else.


-- 
http://sid.rstack.org/
PGP KeyID: 157E98EE FingerPrint: FA62226DA9E72FA8AECAA240008B480E157E98EE
>> Hi! I'm your friendly neighbourhood signature virus.
>> Copy me to your signature file and help me spread!


<Prev in Thread] Current Thread [Next in Thread>