diff options
author | Pablo Neira Ayuso <pablo@netfilter.org> | 2012-03-23 00:02:07 +0100 |
---|---|---|
committer | Pablo Neira Ayuso <pablo@netfilter.org> | 2012-03-23 00:52:08 +0100 |
commit | eeb4cb952386aac764a5cf4cf2490e50a24a8880 (patch) | |
tree | 6f22434bb52107e257493393c5da695453b893e2 /lib/bug.c | |
parent | 1ac0bf99260761ad0a536ddbc15f6f9b82b9bab3 (diff) |
netfilter: xt_CT: fix assignation of the generic protocol tracker
`iptables -p all' uses 0 to match all protocols, while the conntrack
subsystem uses 255. We still need `-p all' to attach the custom
timeout policies for the generic protocol tracker.
Moreover, we may use `iptables -p sctp' while the SCTP tracker is
not loaded. In that case, we have to default on the generic protocol
tracker.
Another possibility is `iptables -p ip' that should be supported
as well. This patch makes sure we validate all possible scenarios.
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'lib/bug.c')
0 files changed, 0 insertions, 0 deletions