Blame view
net/netfilter/Kconfig
38 KB
9fb9cbb10 [NETFILTER]: Add ... |
1 |
menu "Core Netfilter Configuration" |
3a411355b [NETFILTER]: Fix ... |
2 |
depends on NET && INET && NETFILTER |
9fb9cbb10 [NETFILTER]: Add ... |
3 |
|
f9e815b37 [NETFITLER]: Add ... |
4 |
config NETFILTER_NETLINK |
2eeeba390 [NETFILTER]: Sele... |
5 |
tristate |
7af4cc3fa [NETFILTER]: Add ... |
6 |
|
941390279 netfilter: add ex... |
7 8 9 10 11 12 13 |
config NETFILTER_NETLINK_ACCT tristate "Netfilter NFACCT over NFNETLINK interface" depends on NETFILTER_ADVANCED select NETFILTER_NETLINK help If this option is enabled, the kernel will include support for extended accounting via NFNETLINK. |
7af4cc3fa [NETFILTER]: Add ... |
14 15 |
config NETFILTER_NETLINK_QUEUE tristate "Netfilter NFQUEUE over NFNETLINK interface" |
33b8e7760 [NETFILTER]: Add ... |
16 |
depends on NETFILTER_ADVANCED |
2eeeba390 [NETFILTER]: Sele... |
17 |
select NETFILTER_NETLINK |
7af4cc3fa [NETFILTER]: Add ... |
18 |
help |
50b521aa5 [NETFILTER]: Fix ... |
19 |
If this option is enabled, the kernel will include support |
7af4cc3fa [NETFILTER]: Add ... |
20 21 |
for queueing packets via NFNETLINK. |
0597f2680 [NETFILTER]: Add ... |
22 23 |
config NETFILTER_NETLINK_LOG tristate "Netfilter LOG over NFNETLINK interface" |
33b8e7760 [NETFILTER]: Add ... |
24 |
default m if NETFILTER_ADVANCED=n |
2eeeba390 [NETFILTER]: Sele... |
25 |
select NETFILTER_NETLINK |
0597f2680 [NETFILTER]: Add ... |
26 27 28 29 30 31 32 |
help If this option is enabled, the kernel will include support for logging packets via NFNETLINK. This obsoletes the existing ipt_ULOG and ebg_ulog mechanisms, and is also scheduled to replace the old syslog-based ipt_LOG and ip6t_LOG modules. |
ab4f58c77 [NETFILTER]: remo... |
33 |
config NF_CONNTRACK |
b321e1442 [NETFILTER]: Kcon... |
34 |
tristate "Netfilter connection tracking support" |
33b8e7760 [NETFILTER]: Add ... |
35 |
default m if NETFILTER_ADVANCED=n |
b321e1442 [NETFILTER]: Kcon... |
36 |
help |
9fb9cbb10 [NETFILTER]: Add ... |
37 38 39 |
Connection tracking keeps a record of what packets have passed through your machine, in order to figure out how they are related into connections. |
b321e1442 [NETFILTER]: Kcon... |
40 |
This is required to do Masquerading or other kinds of Network |
b11c16beb netfilter: Get ri... |
41 42 |
Address Translation. It can also be used to enhance packet filtering (see `Connection state match support' below). |
b321e1442 [NETFILTER]: Kcon... |
43 44 |
To compile it as a module, choose M here. If unsure, say N. |
c2df73de2 netfilter: xtable... |
45 |
if NF_CONNTRACK |
9fb9cbb10 [NETFILTER]: Add ... |
46 47 |
config NF_CONNTRACK_MARK bool 'Connection mark tracking support' |
33b8e7760 [NETFILTER]: Add ... |
48 |
depends on NETFILTER_ADVANCED |
9fb9cbb10 [NETFILTER]: Add ... |
49 50 51 52 53 |
help This option enables support for connection marks, used by the `CONNMARK' target and `connmark' match. Similar to the mark value of packets, but this mark value is kept in the conntrack session instead of the individual packets. |
7c9728c39 [SECMARK]: Add se... |
54 55 |
config NF_CONNTRACK_SECMARK bool 'Connection tracking security mark support' |
c2df73de2 netfilter: xtable... |
56 |
depends on NETWORK_SECMARK |
33b8e7760 [NETFILTER]: Add ... |
57 |
default m if NETFILTER_ADVANCED=n |
7c9728c39 [SECMARK]: Add se... |
58 59 60 61 62 63 64 65 |
help This option enables security markings to be applied to connections. Typically they are copied to connections from packets using the CONNSECMARK target and copied back from connections to packets with the same target, with the packets being originally labeled via SECMARK. If unsure, say 'N'. |
5d0aa2ccd netfilter: nf_con... |
66 67 68 69 70 71 72 73 74 75 76 77 |
config NF_CONNTRACK_ZONES bool 'Connection tracking zones' depends on NETFILTER_ADVANCED depends on NETFILTER_XT_TARGET_CT help This option enables support for connection tracking zones. Normally, each connection needs to have a unique system wide identity. Connection tracking zones allow to have multiple connections using the same identity, as long as they are contained in different zones. If unsure, say `N'. |
54b07dca6 netfilter: provid... |
78 79 80 81 82 83 84 85 86 |
config NF_CONNTRACK_PROCFS bool "Supply CT list in procfs (OBSOLETE)" default y depends on PROC_FS ---help--- This option enables for the list of known conntrack entries to be shown in procfs under net/netfilter/nf_conntrack. This is considered obsolete in favor of using the conntrack(8) tool which uses Netlink. |
9fb9cbb10 [NETFILTER]: Add ... |
87 |
config NF_CONNTRACK_EVENTS |
8ce22fcab [NETFILTER]: Remo... |
88 |
bool "Connection tracking events" |
33b8e7760 [NETFILTER]: Add ... |
89 |
depends on NETFILTER_ADVANCED |
9fb9cbb10 [NETFILTER]: Add ... |
90 91 92 |
help If this option is enabled, the connection tracking code will provide a notifier chain that can be used by other kernel code |
50b521aa5 [NETFILTER]: Fix ... |
93 |
to get notified about changes in the connection tracking state. |
9fb9cbb10 [NETFILTER]: Add ... |
94 95 |
If unsure, say `N'. |
a992ca2a0 netfilter: nf_con... |
96 97 98 99 100 101 102 103 104 105 |
config NF_CONNTRACK_TIMESTAMP bool 'Connection tracking timestamping' depends on NETFILTER_ADVANCED help This option enables support for connection tracking timestamping. This allows you to store the flow start-time and to obtain the flow-stop time (once it has been destroyed) via Connection tracking events. If unsure, say `N'. |
2bc780499 [NETFILTER]: nf_c... |
106 107 |
config NF_CT_PROTO_DCCP tristate 'DCCP protocol connection tracking support (EXPERIMENTAL)' |
c2df73de2 netfilter: xtable... |
108 |
depends on EXPERIMENTAL |
2bc780499 [NETFILTER]: nf_c... |
109 |
depends on NETFILTER_ADVANCED |
f3261aff3 netfilter: Kconfi... |
110 |
default IP_DCCP |
2bc780499 [NETFILTER]: nf_c... |
111 112 113 114 115 |
help With this option enabled, the layer 3 independent connection tracking code will be able to do state tracking on DCCP connections. If unsure, say 'N'. |
f09943fef [NETFILTER]: nf_c... |
116 117 |
config NF_CT_PROTO_GRE tristate |
f09943fef [NETFILTER]: nf_c... |
118 |
|
9fb9cbb10 [NETFILTER]: Add ... |
119 |
config NF_CT_PROTO_SCTP |
a3c479772 [NETFILTER]: Mark... |
120 |
tristate 'SCTP protocol connection tracking support (EXPERIMENTAL)' |
c2df73de2 netfilter: xtable... |
121 |
depends on EXPERIMENTAL |
33b8e7760 [NETFILTER]: Add ... |
122 |
depends on NETFILTER_ADVANCED |
f3261aff3 netfilter: Kconfi... |
123 |
default IP_SCTP |
9fb9cbb10 [NETFILTER]: Add ... |
124 125 126 127 128 |
help With this option enabled, the layer 3 independent connection tracking code will be able to do state tracking on SCTP connections. If you want to compile it as a module, say M here and read |
39f5fb303 kconfig: fix path... |
129 |
<file:Documentation/kbuild/modules.txt>. If unsure, say `N'. |
9fb9cbb10 [NETFILTER]: Add ... |
130 |
|
59eecdfb1 [NETFILTER]: nf_c... |
131 |
config NF_CT_PROTO_UDPLITE |
8ce22fcab [NETFILTER]: Remo... |
132 |
tristate 'UDP-Lite protocol connection tracking support' |
33b8e7760 [NETFILTER]: Add ... |
133 |
depends on NETFILTER_ADVANCED |
59eecdfb1 [NETFILTER]: nf_c... |
134 135 136 137 138 139 |
help With this option enabled, the layer 3 independent connection tracking code will be able to do state tracking on UDP-Lite connections. To compile it as a module, choose M here. If unsure, say N. |
169589005 [NETFILTER]: nf_c... |
140 |
config NF_CONNTRACK_AMANDA |
c9386cfdd [NETFILTER]: New ... |
141 |
tristate "Amanda backup protocol support" |
33b8e7760 [NETFILTER]: Add ... |
142 |
depends on NETFILTER_ADVANCED |
169589005 [NETFILTER]: nf_c... |
143 144 145 146 147 148 149 150 151 152 153 |
select TEXTSEARCH select TEXTSEARCH_KMP help If you are running the Amanda backup package <http://www.amanda.org/> on this machine or machines that will be MASQUERADED through this machine, then you may want to enable this feature. This allows the connection tracking and natting code to allow the sub-channels that Amanda requires for communication of the backup data, messages and index. To compile it as a module, choose M here. If unsure, say N. |
9fb9cbb10 [NETFILTER]: Add ... |
154 |
config NF_CONNTRACK_FTP |
c9386cfdd [NETFILTER]: New ... |
155 |
tristate "FTP protocol support" |
33b8e7760 [NETFILTER]: Add ... |
156 |
default m if NETFILTER_ADVANCED=n |
9fb9cbb10 [NETFILTER]: Add ... |
157 158 159 160 161 162 163 164 165 166 |
help Tracking FTP connections is problematic: special helpers are required for tracking them, and doing masquerading and other forms of Network Address Translation on them. This is FTP support on Layer 3 independent connection tracking. Layer 3 independent connection tracking is experimental scheme which generalize ip_conntrack to support other layer 3 protocols. To compile it as a module, choose M here. If unsure, say N. |
f587de0e2 [NETFILTER]: nf_c... |
167 |
config NF_CONNTRACK_H323 |
8ce22fcab [NETFILTER]: Remo... |
168 |
tristate "H.323 protocol support" |
c2df73de2 netfilter: xtable... |
169 |
depends on (IPV6 || IPV6=n) |
33b8e7760 [NETFILTER]: Add ... |
170 |
depends on NETFILTER_ADVANCED |
f587de0e2 [NETFILTER]: nf_c... |
171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 |
help H.323 is a VoIP signalling protocol from ITU-T. As one of the most important VoIP protocols, it is widely used by voice hardware and software including voice gateways, IP phones, Netmeeting, OpenPhone, Gnomemeeting, etc. With this module you can support H.323 on a connection tracking/NAT firewall. This module supports RAS, Fast Start, H.245 Tunnelling, Call Forwarding, RTP/RTCP and T.120 based audio, video, fax, chat, whiteboard, file transfer, etc. For more information, please visit http://nath323.sourceforge.net/. To compile it as a module, choose M here. If unsure, say N. |
869f37d8e [NETFILTER]: nf_c... |
186 |
config NF_CONNTRACK_IRC |
c9386cfdd [NETFILTER]: New ... |
187 |
tristate "IRC protocol support" |
33b8e7760 [NETFILTER]: Add ... |
188 |
default m if NETFILTER_ADVANCED=n |
869f37d8e [NETFILTER]: nf_c... |
189 190 191 192 193 194 195 196 197 198 199 |
help There is a commonly-used extension to IRC called Direct Client-to-Client Protocol (DCC). This enables users to send files to each other, and also chat to each other without the need of a server. DCC Sending is used anywhere you send files over IRC, and DCC Chat is most commonly used by Eggdrop bots. If you are using NAT, this extension will enable you to send files and initiate chats. Note that you do NOT need this extension to get files or have others initiate chats, or everything else in IRC. To compile it as a module, choose M here. If unsure, say N. |
93557f53e netfilter: nf_con... |
200 201 |
config NF_CONNTRACK_BROADCAST tristate |
92703eee4 [NETFILTER]: nf_c... |
202 |
config NF_CONNTRACK_NETBIOS_NS |
8ce22fcab [NETFILTER]: Remo... |
203 |
tristate "NetBIOS name service protocol support" |
93557f53e netfilter: nf_con... |
204 |
select NF_CONNTRACK_BROADCAST |
92703eee4 [NETFILTER]: nf_c... |
205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 |
help NetBIOS name service requests are sent as broadcast messages from an unprivileged port and responded to with unicast messages to the same port. This make them hard to firewall properly because connection tracking doesn't deal with broadcasts. This helper tracks locally originating NetBIOS name service requests and the corresponding responses. It relies on correct IP address configuration, specifically netmask and broadcast address. When properly configured, the output of "ip address show" should look similar to this: $ ip -4 address show eth0 4: eth0: <BROADCAST,MULTICAST,UP> mtu 1500 qdisc pfifo_fast qlen 1000 inet 172.16.2.252/24 brd 172.16.2.255 scope global eth0 To compile it as a module, choose M here. If unsure, say N. |
93557f53e netfilter: nf_con... |
220 221 222 223 224 225 226 227 228 229 230 231 232 233 |
config NF_CONNTRACK_SNMP tristate "SNMP service protocol support" depends on NETFILTER_ADVANCED select NF_CONNTRACK_BROADCAST help SNMP service requests are sent as broadcast messages from an unprivileged port and responded to with unicast messages to the same port. This make them hard to firewall properly because connection tracking doesn't deal with broadcasts. This helper tracks locally originating SNMP service requests and the corresponding responses. It relies on correct IP address configuration, specifically netmask and broadcast address. To compile it as a module, choose M here. If unsure, say N. |
f09943fef [NETFILTER]: nf_c... |
234 |
config NF_CONNTRACK_PPTP |
c9386cfdd [NETFILTER]: New ... |
235 |
tristate "PPtP protocol support" |
33b8e7760 [NETFILTER]: Add ... |
236 |
depends on NETFILTER_ADVANCED |
f09943fef [NETFILTER]: nf_c... |
237 238 239 240 241 242 243 244 245 246 |
select NF_CT_PROTO_GRE help This module adds support for PPTP (Point to Point Tunnelling Protocol, RFC2637) connection tracking and NAT. If you are running PPTP sessions over a stateful firewall or NAT box, you may want to enable this feature. Please note that not all PPTP modes of operation are supported yet. Specifically these limitations exist: |
3dde6ad8f Fix trivial typos... |
247 |
- Blindly assumes that control connections are always established |
f09943fef [NETFILTER]: nf_c... |
248 249 250 251 |
in PNS->PAC direction. This is a violation of RFC2637. - Only supports a single call within each session To compile it as a module, choose M here. If unsure, say N. |
6fecd1985 [NETFILTER]: Add ... |
252 253 |
config NF_CONNTRACK_SANE tristate "SANE protocol support (EXPERIMENTAL)" |
c2df73de2 netfilter: xtable... |
254 |
depends on EXPERIMENTAL |
33b8e7760 [NETFILTER]: Add ... |
255 |
depends on NETFILTER_ADVANCED |
6fecd1985 [NETFILTER]: Add ... |
256 257 258 259 260 261 262 263 264 |
help SANE is a protocol for remote access to scanners as implemented by the 'saned' daemon. Like FTP, it uses separate control and data connections. With this module you can support SANE on a connection tracking firewall. To compile it as a module, choose M here. If unsure, say N. |
9fafcd7b2 [NETFILTER]: nf_c... |
265 |
config NF_CONNTRACK_SIP |
8ce22fcab [NETFILTER]: Remo... |
266 |
tristate "SIP protocol support" |
33b8e7760 [NETFILTER]: Add ... |
267 |
default m if NETFILTER_ADVANCED=n |
9fafcd7b2 [NETFILTER]: nf_c... |
268 269 270 271 272 273 274 275 |
help SIP is an application-layer control protocol that can establish, modify, and terminate multimedia sessions (conferences) such as Internet telephony calls. With the ip_conntrack_sip and the nf_nat_sip modules you can support the protocol on a connection tracking/NATing firewall. To compile it as a module, choose M here. If unsure, say N. |
a536df35b [NETFILTER]: nf_c... |
276 |
config NF_CONNTRACK_TFTP |
c9386cfdd [NETFILTER]: New ... |
277 |
tristate "TFTP protocol support" |
33b8e7760 [NETFILTER]: Add ... |
278 |
depends on NETFILTER_ADVANCED |
a536df35b [NETFILTER]: nf_c... |
279 280 281 282 283 284 285 |
help TFTP connection tracking helper, this is required depending on how restrictive your ruleset is. If you are using a tftp client behind -j SNAT or -j MASQUERADING you will need this. To compile it as a module, choose M here. If unsure, say N. |
c1d10adb4 [NETFILTER]: Add ... |
286 |
config NF_CT_NETLINK |
8ce22fcab [NETFILTER]: Remo... |
287 |
tristate 'Connection tracking netlink interface' |
2eeeba390 [NETFILTER]: Sele... |
288 |
select NETFILTER_NETLINK |
33b8e7760 [NETFILTER]: Add ... |
289 |
default m if NETFILTER_ADVANCED=n |
c1d10adb4 [NETFILTER]: Add ... |
290 291 |
help This option enables support for a netlink-based userspace interface |
4b0706624 netfilter: Kconfi... |
292 |
endif # NF_CONNTRACK |
9ad2d745a netfilter: iptabl... |
293 294 295 296 297 298 299 300 301 302 303 304 305 306 |
# transparent proxy support config NETFILTER_TPROXY tristate "Transparent proxying support (EXPERIMENTAL)" depends on EXPERIMENTAL depends on IP_NF_MANGLE depends on NETFILTER_ADVANCED help This option enables transparent proxying support, that is, support for handling non-locally bound IPv4 TCP and UDP sockets. For it to work you will have to configure certain iptables rules and use policy routing. For more information on how to set it up see Documentation/networking/tproxy.txt. To compile it as a module, choose M here. If unsure, say N. |
2e4e6a17a [NETFILTER] x_tab... |
307 308 |
config NETFILTER_XTABLES tristate "Netfilter Xtables support (required for ip_tables)" |
33b8e7760 [NETFILTER]: Add ... |
309 |
default m if NETFILTER_ADVANCED=n |
2e4e6a17a [NETFILTER] x_tab... |
310 311 312 |
help This is required if you intend to use any of ip_tables, ip6_tables or arp_tables. |
c2df73de2 netfilter: xtable... |
313 |
if NETFILTER_XTABLES |
28b949885 netfilter: xtable... |
314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 |
comment "Xtables combined modules" config NETFILTER_XT_MARK tristate 'nfmark target and match support' default m if NETFILTER_ADVANCED=n ---help--- This option adds the "MARK" target and "mark" match. Netfilter mark matching allows you to match packets based on the "nfmark" value in the packet. The target allows you to create rules in the "mangle" table which alter the netfilter mark (nfmark) field associated with the packet. Prior to routing, the nfmark can influence the routing method (see "Use netfilter MARK value as routing key") and can also be used by other subsystems to change their behavior. |
b8f00ba27 netfilter: xtable... |
330 331 332 333 334 335 336 337 338 339 340 |
config NETFILTER_XT_CONNMARK tristate 'ctmark target and match support' depends on NF_CONNTRACK depends on NETFILTER_ADVANCED select NF_CONNTRACK_MARK ---help--- This option adds the "CONNMARK" target and "connmark" match. Netfilter allows you to store a mark value per connection (a.k.a. ctmark), similarly to the packet mark (nfmark). Using this target and match, you can set and match on this mark. |
d956798d8 netfilter: xtable... |
341 342 343 344 345 346 347 348 349 350 351 |
config NETFILTER_XT_SET tristate 'set target and match support' depends on IP_SET depends on NETFILTER_ADVANCED help This option adds the "SET" target and "set" match. Using this target and match, you can add/delete and match elements in the sets created by ipset(8). To compile it as a module, choose M here. If unsure, say N. |
2e4e6a17a [NETFILTER] x_tab... |
352 |
# alphabetically ordered list of targets |
44c587319 netfilter: xtable... |
353 |
comment "Xtables targets" |
43f393cae netfilter: audit ... |
354 355 356 357 358 359 360 361 362 |
config NETFILTER_XT_TARGET_AUDIT tristate "AUDIT target support" depends on AUDIT depends on NETFILTER_ADVANCED ---help--- This option adds a 'AUDIT' target, which can be used to create audit records for packets dropped/accepted. To compileit as a module, choose M here. If unsure, say N. |
edf0e1fb0 netfilter: add CH... |
363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 |
config NETFILTER_XT_TARGET_CHECKSUM tristate "CHECKSUM target support" depends on IP_NF_MANGLE || IP6_NF_MANGLE depends on NETFILTER_ADVANCED ---help--- This option adds a `CHECKSUM' target, which can be used in the iptables mangle table. You can use this target to compute and fill in the checksum in a packet that lacks a checksum. This is particularly useful, if you need to work around old applications such as dhcp clients, that do not work well with checksum offloads, but don't want to disable checksum offload in your device. To compile it as a module, choose M here. If unsure, say N. |
2e4e6a17a [NETFILTER] x_tab... |
378 379 |
config NETFILTER_XT_TARGET_CLASSIFY tristate '"CLASSIFY" target support' |
33b8e7760 [NETFILTER]: Add ... |
380 |
depends on NETFILTER_ADVANCED |
2e4e6a17a [NETFILTER] x_tab... |
381 382 383 384 385 386 387 388 389 390 391 |
help This option adds a `CLASSIFY' target, which enables the user to set the priority of a packet. Some qdiscs can use this value for classification, among these are: atm, cbq, dsmark, pfifo_fast, htb, prio To compile it as a module, choose M here. If unsure, say N. config NETFILTER_XT_TARGET_CONNMARK tristate '"CONNMARK" target support' |
587aa6416 [NETFILTER]: Remo... |
392 |
depends on NF_CONNTRACK |
33b8e7760 [NETFILTER]: Add ... |
393 |
depends on NETFILTER_ADVANCED |
b8f00ba27 netfilter: xtable... |
394 395 396 397 398 |
select NETFILTER_XT_CONNMARK ---help--- This is a backwards-compat option for the user's convenience (e.g. when running oldconfig). It selects CONFIG_NETFILTER_XT_CONNMARK (combined connmark/CONNMARK module). |
2e4e6a17a [NETFILTER] x_tab... |
399 |
|
aba0d3480 netfilter: xtable... |
400 401 |
config NETFILTER_XT_TARGET_CONNSECMARK tristate '"CONNSECMARK" target support' |
c2df73de2 netfilter: xtable... |
402 |
depends on NF_CONNTRACK && NF_CONNTRACK_SECMARK |
aba0d3480 netfilter: xtable... |
403 404 405 406 407 408 409 410 |
default m if NETFILTER_ADVANCED=n help The CONNSECMARK target copies security markings from packets to connections, and restores security markings from connections to packets (if the packets are not already marked). This would normally be used in conjunction with the SECMARK target. To compile it as a module, choose M here. If unsure, say N. |
84f3bb9ae netfilter: xtable... |
411 412 413 414 415 416 417 418 419 420 421 |
config NETFILTER_XT_TARGET_CT tristate '"CT" target support' depends on NF_CONNTRACK depends on IP_NF_RAW || IP6_NF_RAW depends on NETFILTER_ADVANCED help This options adds a `CT' target, which allows to specify initial connection tracking parameters like events to be delivered and the helper to be used. To compile it as a module, choose M here. If unsure, say N. |
a468701db [NETFILTER]: x_ta... |
422 |
config NETFILTER_XT_TARGET_DSCP |
c9fd49680 [NETFILTER]: Merg... |
423 |
tristate '"DSCP" and "TOS" target support' |
a468701db [NETFILTER]: x_ta... |
424 |
depends on IP_NF_MANGLE || IP6_NF_MANGLE |
33b8e7760 [NETFILTER]: Add ... |
425 |
depends on NETFILTER_ADVANCED |
a468701db [NETFILTER]: x_ta... |
426 427 428 429 430 |
help This option adds a `DSCP' target, which allows you to manipulate the IPv4/IPv6 header DSCP field (differentiated services codepoint). The DSCP field can have any value between 0x0 and 0x3f inclusive. |
c9fd49680 [NETFILTER]: Merg... |
431 432 |
It also adds the "TOS" target, which allows you to create rules in the "mangle" table which alter the Type Of Service field of an IPv4 |
5c350e5a3 [NETFILTER]: IPv6... |
433 |
or the Priority field of an IPv6 packet, prior to routing. |
c9fd49680 [NETFILTER]: Merg... |
434 |
|
a468701db [NETFILTER]: x_ta... |
435 |
To compile it as a module, choose M here. If unsure, say N. |
563d36eb3 netfilter: Combin... |
436 437 438 439 440 441 442 443 444 445 446 447 448 449 |
config NETFILTER_XT_TARGET_HL tristate '"HL" hoplimit target support' depends on IP_NF_MANGLE || IP6_NF_MANGLE depends on NETFILTER_ADVANCED ---help--- This option adds the "HL" (for IPv6) and "TTL" (for IPv4) targets, which enable the user to change the hoplimit/time-to-live value of the IP header. While it is safe to decrement the hoplimit/TTL value, the modules also allow to increment and set the hoplimit value of the header to arbitrary values. This is EXTREMELY DANGEROUS since you can easily create immortal packets that loop forever on the network. |
0902b469b netfilter: xtable... |
450 451 452 453 454 455 456 457 458 459 460 |
config NETFILTER_XT_TARGET_IDLETIMER tristate "IDLETIMER target support" depends on NETFILTER_ADVANCED help This option adds the `IDLETIMER' target. Each matching packet resets the timer associated with label specified when the rule is added. When the timer expires, it triggers a sysfs notification. The remaining time for expiration can be read via sysfs. To compile it as a module, choose M here. If unsure, say N. |
268cb38e1 netfilter: x_tabl... |
461 462 |
config NETFILTER_XT_TARGET_LED tristate '"LED" target support' |
3ae16f130 netfilter: fix se... |
463 |
depends on LEDS_CLASS && LEDS_TRIGGERS |
268cb38e1 netfilter: x_tabl... |
464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482 |
depends on NETFILTER_ADVANCED help This option adds a `LED' target, which allows you to blink LEDs in response to particular packets passing through your machine. This can be used to turn a spare LED into a network activity LED, which only flashes in response to FTP transfers, for example. Or you could have an LED which lights up for a minute or two every time somebody connects to your machine via SSH. You will need support for the "led" class to make this work. To create an LED trigger for incoming SSH traffic: iptables -A INPUT -p tcp --dport 22 -j LED --led-trigger-id ssh --led-delay 1000 Then attach the new trigger to an LED on your system: echo netfilter-ssh > /sys/class/leds/<ledname>/trigger For more information on the LEDs available on your system, see |
395cf9691 doc: fix broken r... |
483 |
Documentation/leds/leds-class.txt |
268cb38e1 netfilter: x_tabl... |
484 |
|
2e4e6a17a [NETFILTER] x_tab... |
485 486 |
config NETFILTER_XT_TARGET_MARK tristate '"MARK" target support' |
28b949885 netfilter: xtable... |
487 488 489 490 491 492 |
depends on NETFILTER_ADVANCED select NETFILTER_XT_MARK ---help--- This is a backwards-compat option for the user's convenience (e.g. when running oldconfig). It selects CONFIG_NETFILTER_XT_MARK (combined mark/MARK module). |
2e4e6a17a [NETFILTER] x_tab... |
493 |
|
baf7b1e11 [NETFILTER]: x_ta... |
494 495 |
config NETFILTER_XT_TARGET_NFLOG tristate '"NFLOG" target support' |
33b8e7760 [NETFILTER]: Add ... |
496 |
default m if NETFILTER_ADVANCED=n |
293a4f283 netfilter: xt_NFL... |
497 |
select NETFILTER_NETLINK_LOG |
baf7b1e11 [NETFILTER]: x_ta... |
498 499 |
help This option enables the NFLOG target, which allows to LOG |
293a4f283 netfilter: xt_NFL... |
500 |
messages through nfnetlink_log. |
baf7b1e11 [NETFILTER]: x_ta... |
501 502 |
To compile it as a module, choose M here. If unsure, say N. |
aba0d3480 netfilter: xtable... |
503 504 |
config NETFILTER_XT_TARGET_NFQUEUE tristate '"NFQUEUE" target Support' |
aba0d3480 netfilter: xtable... |
505 |
depends on NETFILTER_ADVANCED |
5f2cafe73 netfilter: Kconfi... |
506 |
select NETFILTER_NETLINK_QUEUE |
aba0d3480 netfilter: xtable... |
507 508 509 510 511 512 513 |
help This target replaced the old obsolete QUEUE target. As opposed to QUEUE, it supports 65535 different queues, not just one. To compile it as a module, choose M here. If unsure, say N. |
2e4e6a17a [NETFILTER] x_tab... |
514 515 |
config NETFILTER_XT_TARGET_NOTRACK tristate '"NOTRACK" target support' |
2e4e6a17a [NETFILTER] x_tab... |
516 |
depends on IP_NF_RAW || IP6_NF_RAW |
587aa6416 [NETFILTER]: Remo... |
517 |
depends on NF_CONNTRACK |
2e4e6a17a [NETFILTER] x_tab... |
518 519 520 521 522 |
help The NOTRACK target allows a select rule to specify which packets *not* to enter the conntrack/NAT subsystem with all the consequences (no ICMP error tracking, no protocol helpers for the selected packets). |
33b8e7760 [NETFILTER]: Add ... |
523 |
|
2e4e6a17a [NETFILTER] x_tab... |
524 |
If you want to compile it as a module, say M here and read |
39f5fb303 kconfig: fix path... |
525 |
<file:Documentation/kbuild/modules.txt>. If unsure, say `N'. |
2e4e6a17a [NETFILTER] x_tab... |
526 |
|
5859034d7 [NETFILTER]: x_ta... |
527 528 |
config NETFILTER_XT_TARGET_RATEEST tristate '"RATEEST" target support' |
b26e76b7c [NETFILTER]: Hide... |
529 |
depends on NETFILTER_ADVANCED |
5859034d7 [NETFILTER]: x_ta... |
530 531 532 533 534 535 |
help This option adds a `RATEEST' target, which allows to measure rates similar to TC estimators. The `rateest' match can be used to match on the measured rates. To compile it as a module, choose M here. If unsure, say N. |
e281b1989 netfilter: xtable... |
536 |
config NETFILTER_XT_TARGET_TEE |
fe6fb5528 netfilter: fix si... |
537 |
tristate '"TEE" - packet cloning to alternate destination' |
e281b1989 netfilter: xtable... |
538 |
depends on NETFILTER_ADVANCED |
9b7ce2b76 netfilter: xtable... |
539 |
depends on (IPV6 || IPV6=n) |
83827f6a8 netfilter: xt_TEE... |
540 |
depends on !NF_CONNTRACK || NF_CONNTRACK |
e281b1989 netfilter: xtable... |
541 542 543 |
---help--- This option adds a "TEE" target with which a packet can be cloned and this clone be rerouted to another nexthop. |
e84392707 netfilter: iptabl... |
544 545 546 547 548 549 550 |
config NETFILTER_XT_TARGET_TPROXY tristate '"TPROXY" target support (EXPERIMENTAL)' depends on EXPERIMENTAL depends on NETFILTER_TPROXY depends on NETFILTER_XTABLES depends on NETFILTER_ADVANCED select NF_DEFRAG_IPV4 |
f6318e558 netfilter: fix mo... |
551 |
select NF_DEFRAG_IPV6 if IP6_NF_IPTABLES |
e84392707 netfilter: iptabl... |
552 553 554 555 556 557 558 |
help This option adds a `TPROXY' target, which is somewhat similar to REDIRECT. It can only be used in the mangle table and is useful to redirect traffic to a transparent proxy. It does _not_ depend on Netfilter connection tracking and NAT, unlike REDIRECT. To compile it as a module, choose M here. If unsure, say N. |
ba9dda3ab [NETFILTER]: x_ta... |
559 560 |
config NETFILTER_XT_TARGET_TRACE tristate '"TRACE" target support' |
ba9dda3ab [NETFILTER]: x_ta... |
561 |
depends on IP_NF_RAW || IP6_NF_RAW |
33b8e7760 [NETFILTER]: Add ... |
562 |
depends on NETFILTER_ADVANCED |
ba9dda3ab [NETFILTER]: x_ta... |
563 564 565 566 567 568 |
help The TRACE target allows you to mark packets so that the kernel will log every rule which match the packets as those traverse the tables, chains, rules. If you want to compile it as a module, say M here and read |
e403149c9 Kbuild/doc: fix l... |
569 |
<file:Documentation/kbuild/modules.txt>. If unsure, say `N'. |
ba9dda3ab [NETFILTER]: x_ta... |
570 |
|
5e6874cdb [SECMARK]: Add xt... |
571 572 |
config NETFILTER_XT_TARGET_SECMARK tristate '"SECMARK" target support' |
c2df73de2 netfilter: xtable... |
573 |
depends on NETWORK_SECMARK |
33b8e7760 [NETFILTER]: Add ... |
574 |
default m if NETFILTER_ADVANCED=n |
5e6874cdb [SECMARK]: Add xt... |
575 576 577 578 579 |
help The SECMARK target allows security marking of network packets, for use with security subsystems. To compile it as a module, choose M here. If unsure, say N. |
cdd289a2f [NETFILTER]: add ... |
580 581 |
config NETFILTER_XT_TARGET_TCPMSS tristate '"TCPMSS" target support' |
c2df73de2 netfilter: xtable... |
582 |
depends on (IPV6 || IPV6=n) |
33b8e7760 [NETFILTER]: Add ... |
583 |
default m if NETFILTER_ADVANCED=n |
cdd289a2f [NETFILTER]: add ... |
584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 |
---help--- This option adds a `TCPMSS' target, which allows you to alter the MSS value of TCP SYN packets, to control the maximum size for that connection (usually limiting it to your outgoing interface's MTU minus 40). This is used to overcome criminally braindead ISPs or servers which block ICMP Fragmentation Needed packets. The symptoms of this problem are that everything works fine from your Linux firewall/router, but machines behind it can never exchange large packets: 1) Web browsers connect, then hang with no data received. 2) Small mail works fine, but large emails hang. 3) ssh works fine, but scp hangs after initial handshaking. Workaround: activate this option and add a rule to your firewall configuration like: iptables -A FORWARD -p tcp --tcp-flags SYN,RST SYN \ -j TCPMSS --clamp-mss-to-pmtu To compile it as a module, choose M here. If unsure, say N. |
338e8a792 [NETFILTER]: x_ta... |
606 607 |
config NETFILTER_XT_TARGET_TCPOPTSTRIP tristate '"TCPOPTSTRIP" target support (EXPERIMENTAL)' |
c2df73de2 netfilter: xtable... |
608 |
depends on EXPERIMENTAL |
338e8a792 [NETFILTER]: x_ta... |
609 |
depends on IP_NF_MANGLE || IP6_NF_MANGLE |
33b8e7760 [NETFILTER]: Add ... |
610 |
depends on NETFILTER_ADVANCED |
338e8a792 [NETFILTER]: x_ta... |
611 612 613 |
help This option adds a "TCPOPTSTRIP" target, which allows you to strip TCP options from TCP packets. |
44c587319 netfilter: xtable... |
614 615 616 |
# alphabetically ordered list of matches comment "Xtables matches" |
de81bbea1 netfilter: ipt_ad... |
617 618 619 620 621 622 623 624 625 |
config NETFILTER_XT_MATCH_ADDRTYPE tristate '"addrtype" address type match support' depends on NETFILTER_ADVANCED ---help--- This option allows you to match what routing thinks of an address, eg. UNICAST, LOCAL, BROADCAST, ... If you want to compile it as a module, say M here and read <file:Documentation/kbuild/modules.txt>. If unsure, say `N'. |
0269ea493 netfilter: xtable... |
626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 |
config NETFILTER_XT_MATCH_CLUSTER tristate '"cluster" match support' depends on NF_CONNTRACK depends on NETFILTER_ADVANCED ---help--- This option allows you to build work-load-sharing clusters of network servers/stateful firewalls without having a dedicated load-balancing router/server/switch. Basically, this match returns true when the packet must be handled by this cluster node. Thus, all nodes see all packets and this match decides which node handles what packets. The work-load sharing algorithm is based on source address hashing. If you say Y or M here, try `iptables -m cluster --help` for more information. |
2e4e6a17a [NETFILTER] x_tab... |
641 642 |
config NETFILTER_XT_MATCH_COMMENT tristate '"comment" match support' |
33b8e7760 [NETFILTER]: Add ... |
643 |
depends on NETFILTER_ADVANCED |
2e4e6a17a [NETFILTER] x_tab... |
644 645 646 647 648 |
help This option adds a `comment' dummy-match, which allows you to put comments in your iptables ruleset. If you want to compile it as a module, say M here and read |
39f5fb303 kconfig: fix path... |
649 |
<file:Documentation/kbuild/modules.txt>. If unsure, say `N'. |
2e4e6a17a [NETFILTER] x_tab... |
650 651 652 |
config NETFILTER_XT_MATCH_CONNBYTES tristate '"connbytes" per-connection counter match support' |
587aa6416 [NETFILTER]: Remo... |
653 |
depends on NF_CONNTRACK |
33b8e7760 [NETFILTER]: Add ... |
654 |
depends on NETFILTER_ADVANCED |
2e4e6a17a [NETFILTER] x_tab... |
655 656 657 658 659 |
help This option adds a `connbytes' match, which allows you to match the number of bytes and/or packets for each direction within a connection. If you want to compile it as a module, say M here and read |
39f5fb303 kconfig: fix path... |
660 |
<file:Documentation/kbuild/modules.txt>. If unsure, say `N'. |
2e4e6a17a [NETFILTER] x_tab... |
661 |
|
370786f9c [NETFILTER]: x_ta... |
662 663 |
config NETFILTER_XT_MATCH_CONNLIMIT tristate '"connlimit" match support"' |
3fd8f9e4b [NETFILTER]: xt_c... |
664 |
depends on NF_CONNTRACK |
33b8e7760 [NETFILTER]: Add ... |
665 |
depends on NETFILTER_ADVANCED |
370786f9c [NETFILTER]: x_ta... |
666 667 668 |
---help--- This match allows you to match against the number of parallel connections to a server per client IP address (or address block). |
2e4e6a17a [NETFILTER] x_tab... |
669 670 |
config NETFILTER_XT_MATCH_CONNMARK tristate '"connmark" connection mark match support' |
587aa6416 [NETFILTER]: Remo... |
671 |
depends on NF_CONNTRACK |
33b8e7760 [NETFILTER]: Add ... |
672 |
depends on NETFILTER_ADVANCED |
b8f00ba27 netfilter: xtable... |
673 674 675 676 677 |
select NETFILTER_XT_CONNMARK ---help--- This is a backwards-compat option for the user's convenience (e.g. when running oldconfig). It selects CONFIG_NETFILTER_XT_CONNMARK (combined connmark/CONNMARK module). |
2e4e6a17a [NETFILTER] x_tab... |
678 679 680 |
config NETFILTER_XT_MATCH_CONNTRACK tristate '"conntrack" connection tracking match support' |
587aa6416 [NETFILTER]: Remo... |
681 |
depends on NF_CONNTRACK |
33b8e7760 [NETFILTER]: Add ... |
682 |
default m if NETFILTER_ADVANCED=n |
2e4e6a17a [NETFILTER] x_tab... |
683 684 685 686 687 688 689 690 |
help This is a general conntrack match module, a superset of the state match. It allows matching on additional conntrack information, which is useful in complex configurations, such as NAT gateways with multiple internet links or tunnels. To compile it as a module, choose M here. If unsure, say N. |
e8648a1fd netfilter: add xt... |
691 692 693 694 695 696 697 698 699 |
config NETFILTER_XT_MATCH_CPU tristate '"cpu" match support' depends on NETFILTER_ADVANCED help CPU matching allows you to match packets based on the CPU currently handling the packet. To compile it as a module, choose M here. If unsure, say N. |
2e4e6a17a [NETFILTER] x_tab... |
700 701 |
config NETFILTER_XT_MATCH_DCCP |
4c37799cc [NETFILTER]: Use ... |
702 |
tristate '"dccp" protocol match support' |
33b8e7760 [NETFILTER]: Add ... |
703 |
depends on NETFILTER_ADVANCED |
f3261aff3 netfilter: Kconfi... |
704 |
default IP_DCCP |
2e4e6a17a [NETFILTER] x_tab... |
705 706 707 708 709 710 |
help With this option enabled, you will be able to use the iptables `dccp' match in order to match on DCCP source/destination ports and DCCP flags. If you want to compile it as a module, say M here and read |
39f5fb303 kconfig: fix path... |
711 |
<file:Documentation/kbuild/modules.txt>. If unsure, say `N'. |
2e4e6a17a [NETFILTER] x_tab... |
712 |
|
9291747f1 netfilter: xtable... |
713 714 715 716 717 718 719 720 |
config NETFILTER_XT_MATCH_DEVGROUP tristate '"devgroup" match support' depends on NETFILTER_ADVANCED help This options adds a `devgroup' match, which allows to match on the device group a network device is assigned to. To compile it as a module, choose M here. If unsure, say N. |
9ba162761 [NETFILTER]: x_ta... |
721 |
config NETFILTER_XT_MATCH_DSCP |
c3b33e6a2 [NETFILTER]: Merg... |
722 |
tristate '"dscp" and "tos" match support' |
33b8e7760 [NETFILTER]: Add ... |
723 |
depends on NETFILTER_ADVANCED |
9ba162761 [NETFILTER]: x_ta... |
724 725 726 727 728 |
help This option adds a `DSCP' match, which allows you to match against the IPv4/IPv6 header DSCP field (differentiated services codepoint). The DSCP field can have any value between 0x0 and 0x3f inclusive. |
c3b33e6a2 [NETFILTER]: Merg... |
729 730 731 |
It will also add a "tos" match, which allows you to match packets based on the Type Of Service fields of the IPv4 packet (which share the same bits as DSCP). |
9ba162761 [NETFILTER]: x_ta... |
732 |
To compile it as a module, choose M here. If unsure, say N. |
d446a8202 netfilter: xtable... |
733 734 735 736 737 738 739 740 |
config NETFILTER_XT_MATCH_ECN tristate '"ecn" match support' depends on NETFILTER_ADVANCED ---help--- This option adds an "ECN" match, which allows you to match against the IPv4 and TCP header ECN fields. To compile it as a module, choose M here. If unsure, say N. |
dc5ab2fae [NETFILTER]: x_ta... |
741 |
config NETFILTER_XT_MATCH_ESP |
4c37799cc [NETFILTER]: Use ... |
742 |
tristate '"esp" match support' |
33b8e7760 [NETFILTER]: Add ... |
743 |
depends on NETFILTER_ADVANCED |
dc5ab2fae [NETFILTER]: x_ta... |
744 745 746 747 748 |
help This match extension allows you to match a range of SPIs inside ESP header of IPSec packets. To compile it as a module, choose M here. If unsure, say N. |
aba0d3480 netfilter: xtable... |
749 750 |
config NETFILTER_XT_MATCH_HASHLIMIT tristate '"hashlimit" match support' |
c2df73de2 netfilter: xtable... |
751 |
depends on (IP6_NF_IPTABLES || IP6_NF_IPTABLES=n) |
aba0d3480 netfilter: xtable... |
752 753 754 755 756 757 758 759 760 761 762 |
depends on NETFILTER_ADVANCED help This option adds a `hashlimit' match. As opposed to `limit', this match dynamically creates a hash table of limit buckets, based on your selection of source/destination addresses and/or ports. It enables you to express policies like `10kpps for any given destination address' or `500pps from any given source address' with a single rule. |
2e4e6a17a [NETFILTER] x_tab... |
763 764 |
config NETFILTER_XT_MATCH_HELPER tristate '"helper" match support' |
587aa6416 [NETFILTER]: Remo... |
765 |
depends on NF_CONNTRACK |
33b8e7760 [NETFILTER]: Add ... |
766 |
depends on NETFILTER_ADVANCED |
2e4e6a17a [NETFILTER] x_tab... |
767 768 769 770 771 |
help Helper matching allows you to match packets in dynamic connections tracked by a conntrack-helper, ie. ip_conntrack_ftp To compile it as a module, choose M here. If unsure, say Y. |
cfac5ef7b netfilter: Combin... |
772 773 774 775 776 777 778 |
config NETFILTER_XT_MATCH_HL tristate '"hl" hoplimit/TTL match support' depends on NETFILTER_ADVANCED ---help--- HL matching allows you to match packets based on the hoplimit in the IPv6 header, or the time-to-live field in the IPv4 header of the packet. |
f72e25a89 [NETFILTER]: Rena... |
779 780 |
config NETFILTER_XT_MATCH_IPRANGE tristate '"iprange" address range match support' |
f72e25a89 [NETFILTER]: Rena... |
781 782 783 784 785 786 787 |
depends on NETFILTER_ADVANCED ---help--- This option adds a "iprange" match, which allows you to match based on an IP address range. (Normal iptables only matches on single addresses with an optional mask.) If unsure, say M. |
9c3e1c396 netfilter: xt_ipv... |
788 789 790 791 792 793 794 795 796 |
config NETFILTER_XT_MATCH_IPVS tristate '"ipvs" match support' depends on IP_VS depends on NETFILTER_ADVANCED depends on NF_CONNTRACK help This option allows you to match against IPVS properties of a packet. If unsure, say N. |
2e4e6a17a [NETFILTER] x_tab... |
797 798 |
config NETFILTER_XT_MATCH_LENGTH tristate '"length" match support' |
33b8e7760 [NETFILTER]: Add ... |
799 |
depends on NETFILTER_ADVANCED |
2e4e6a17a [NETFILTER] x_tab... |
800 801 802 803 804 805 806 807 |
help This option allows you to match the length of a packet against a specific value or range of values. To compile it as a module, choose M here. If unsure, say N. config NETFILTER_XT_MATCH_LIMIT tristate '"limit" match support' |
33b8e7760 [NETFILTER]: Add ... |
808 |
depends on NETFILTER_ADVANCED |
2e4e6a17a [NETFILTER] x_tab... |
809 810 811 812 813 814 815 816 817 |
help limit matching allows you to control the rate at which a rule can be matched: mainly useful in combination with the LOG target ("LOG target support", below) and to avoid some Denial of Service attacks. To compile it as a module, choose M here. If unsure, say N. config NETFILTER_XT_MATCH_MAC tristate '"mac" address match support' |
33b8e7760 [NETFILTER]: Add ... |
818 |
depends on NETFILTER_ADVANCED |
2e4e6a17a [NETFILTER] x_tab... |
819 820 821 822 823 824 825 826 |
help MAC matching allows you to match packets based on the source Ethernet address of the packet. To compile it as a module, choose M here. If unsure, say N. config NETFILTER_XT_MATCH_MARK tristate '"mark" match support' |
28b949885 netfilter: xtable... |
827 828 829 830 831 832 |
depends on NETFILTER_ADVANCED select NETFILTER_XT_MARK ---help--- This is a backwards-compat option for the user's convenience (e.g. when running oldconfig). It selects CONFIG_NETFILTER_XT_MARK (combined mark/MARK module). |
2e4e6a17a [NETFILTER] x_tab... |
833 |
|
aba0d3480 netfilter: xtable... |
834 835 |
config NETFILTER_XT_MATCH_MULTIPORT tristate '"multiport" Multiple port match support' |
aba0d3480 netfilter: xtable... |
836 837 838 839 840 841 842 |
depends on NETFILTER_ADVANCED help Multiport matching allows you to match TCP or UDP packets based on a series of source or destination ports: normally a rule can only match a single range of ports. To compile it as a module, choose M here. If unsure, say N. |
ceb98d03e netfilter: xtable... |
843 844 |
config NETFILTER_XT_MATCH_NFACCT tristate '"nfacct" match support' |
bc94b5216 netfilter: Kconfi... |
845 |
depends on NETFILTER_ADVANCED |
ceb98d03e netfilter: xtable... |
846 847 848 849 850 851 |
select NETFILTER_NETLINK_ACCT help This option allows you to use the extended accounting through nfnetlink_acct. To compile it as a module, choose M here. If unsure, say N. |
115bc8f28 netfilter: xtable... |
852 853 854 855 856 857 858 859 860 861 862 863 |
config NETFILTER_XT_MATCH_OSF tristate '"osf" Passive OS fingerprint match' depends on NETFILTER_ADVANCED && NETFILTER_NETLINK help This option selects the Passive OS Fingerprinting match module that allows to passively match the remote operating system by analyzing incoming TCP SYN packets. Rules and loading software can be downloaded from http://www.ioremap.net/projects/osf To compile it as a module, choose M here. If unsure, say N. |
0265ab44b [NETFILTER]: merg... |
864 865 |
config NETFILTER_XT_MATCH_OWNER tristate '"owner" match support' |
33b8e7760 [NETFILTER]: Add ... |
866 |
depends on NETFILTER_ADVANCED |
0265ab44b [NETFILTER]: merg... |
867 868 869 870 |
---help--- Socket owner matching allows you to match locally-generated packets based on who created the socket: the user or group. It is also possible to check whether a socket actually exists. |
c4b885139 [NETFILTER]: x_ta... |
871 872 |
config NETFILTER_XT_MATCH_POLICY tristate 'IPsec "policy" match support' |
c2df73de2 netfilter: xtable... |
873 |
depends on XFRM |
33b8e7760 [NETFILTER]: Add ... |
874 |
default m if NETFILTER_ADVANCED=n |
c4b885139 [NETFILTER]: x_ta... |
875 876 877 878 879 880 |
help Policy matching allows you to match packets based on the IPsec policy that was used during decapsulation/will be used during encapsulation. To compile it as a module, choose M here. If unsure, say N. |
2e4e6a17a [NETFILTER] x_tab... |
881 882 |
config NETFILTER_XT_MATCH_PHYSDEV tristate '"physdev" match support' |
c2df73de2 netfilter: xtable... |
883 |
depends on BRIDGE && BRIDGE_NETFILTER |
33b8e7760 [NETFILTER]: Add ... |
884 |
depends on NETFILTER_ADVANCED |
2e4e6a17a [NETFILTER] x_tab... |
885 886 887 888 889 890 891 892 |
help Physdev packet matching matches against the physical bridge ports the IP packet arrived on or will leave by. To compile it as a module, choose M here. If unsure, say N. config NETFILTER_XT_MATCH_PKTTYPE tristate '"pkttype" packet type match support' |
33b8e7760 [NETFILTER]: Add ... |
893 |
depends on NETFILTER_ADVANCED |
2e4e6a17a [NETFILTER] x_tab... |
894 895 896 897 898 899 900 901 |
help Packet type matching allows you to match a packet by its "class", eg. BROADCAST, MULTICAST, ... Typical usage: iptables -A INPUT -m pkttype --pkt-type broadcast -j LOG To compile it as a module, choose M here. If unsure, say N. |
62b774348 [NETFILTER]: x_ta... |
902 903 |
config NETFILTER_XT_MATCH_QUOTA tristate '"quota" match support' |
33b8e7760 [NETFILTER]: Add ... |
904 |
depends on NETFILTER_ADVANCED |
62b774348 [NETFILTER]: x_ta... |
905 906 907 908 909 |
help This option adds a `quota' match, which allows to match on a byte counter. If you want to compile it as a module, say M here and read |
39f5fb303 kconfig: fix path... |
910 |
<file:Documentation/kbuild/modules.txt>. If unsure, say `N'. |
62b774348 [NETFILTER]: x_ta... |
911 |
|
50c164a81 [NETFILTER]: x_ta... |
912 913 |
config NETFILTER_XT_MATCH_RATEEST tristate '"rateest" match support' |
b26e76b7c [NETFILTER]: Hide... |
914 |
depends on NETFILTER_ADVANCED |
50c164a81 [NETFILTER]: x_ta... |
915 916 917 918 919 920 |
select NETFILTER_XT_TARGET_RATEEST help This option adds a `rateest' match, which allows to match on the rate estimated by the RATEEST target. To compile it as a module, choose M here. If unsure, say N. |
2e4e6a17a [NETFILTER] x_tab... |
921 922 |
config NETFILTER_XT_MATCH_REALM tristate '"realm" match support' |
33b8e7760 [NETFILTER]: Add ... |
923 |
depends on NETFILTER_ADVANCED |
c7066f70d netfilter: fix Kc... |
924 |
select IP_ROUTE_CLASSID |
2e4e6a17a [NETFILTER] x_tab... |
925 926 927 |
help This option adds a `realm' match, which allows you to use the realm key from the routing subsystem inside iptables. |
33b8e7760 [NETFILTER]: Add ... |
928 |
|
2e4e6a17a [NETFILTER] x_tab... |
929 930 |
This match pretty much resembles the CONFIG_NET_CLS_ROUTE4 option in tc world. |
33b8e7760 [NETFILTER]: Add ... |
931 |
|
2e4e6a17a [NETFILTER] x_tab... |
932 |
If you want to compile it as a module, say M here and read |
39f5fb303 kconfig: fix path... |
933 |
<file:Documentation/kbuild/modules.txt>. If unsure, say `N'. |
2e4e6a17a [NETFILTER] x_tab... |
934 |
|
e948b20a7 netfilter: rename... |
935 936 |
config NETFILTER_XT_MATCH_RECENT tristate '"recent" match support' |
e948b20a7 netfilter: rename... |
937 938 939 940 941 942 943 |
depends on NETFILTER_ADVANCED ---help--- This match is used for creating one or many lists of recently used addresses and then matching against that/those list(s). Short options are available by using 'iptables -m recent -h' Official Website: <http://snowman.net/projects/ipt_recent/> |
2e4e6a17a [NETFILTER] x_tab... |
944 |
config NETFILTER_XT_MATCH_SCTP |
d5af981e9 [NETFILTER]: Demo... |
945 |
tristate '"sctp" protocol match support (EXPERIMENTAL)' |
c2df73de2 netfilter: xtable... |
946 |
depends on EXPERIMENTAL |
33b8e7760 [NETFILTER]: Add ... |
947 |
depends on NETFILTER_ADVANCED |
f3261aff3 netfilter: Kconfi... |
948 |
default IP_SCTP |
2e4e6a17a [NETFILTER] x_tab... |
949 950 951 952 953 954 |
help With this option enabled, you will be able to use the `sctp' match in order to match on SCTP source/destination ports and SCTP chunk types. If you want to compile it as a module, say M here and read |
39f5fb303 kconfig: fix path... |
955 |
<file:Documentation/kbuild/modules.txt>. If unsure, say `N'. |
2e4e6a17a [NETFILTER] x_tab... |
956 |
|
136cdc71f netfilter: iptabl... |
957 958 959 960 961 962 |
config NETFILTER_XT_MATCH_SOCKET tristate '"socket" match support (EXPERIMENTAL)' depends on EXPERIMENTAL depends on NETFILTER_TPROXY depends on NETFILTER_XTABLES depends on NETFILTER_ADVANCED |
acda07439 xt_socket: checks... |
963 |
depends on !NF_CONNTRACK || NF_CONNTRACK |
136cdc71f netfilter: iptabl... |
964 |
select NF_DEFRAG_IPV4 |
f6318e558 netfilter: fix mo... |
965 |
select NF_DEFRAG_IPV6 if IP6_NF_IPTABLES |
136cdc71f netfilter: iptabl... |
966 967 968 969 970 971 972 |
help This option adds a `socket' match, which can be used to match packets for which a TCP or UDP socket lookup finds a valid socket. It can be used in combination with the MARK target and policy routing to implement full featured non-locally bound sockets. To compile it as a module, choose M here. If unsure, say N. |
2e4e6a17a [NETFILTER] x_tab... |
973 974 |
config NETFILTER_XT_MATCH_STATE tristate '"state" match support' |
587aa6416 [NETFILTER]: Remo... |
975 |
depends on NF_CONNTRACK |
33b8e7760 [NETFILTER]: Add ... |
976 |
default m if NETFILTER_ADVANCED=n |
2e4e6a17a [NETFILTER] x_tab... |
977 978 979 980 981 982 |
help Connection state matching allows you to match packets based on their relationship to a tracked connection (ie. previous packets). This is a powerful tool for packet classification. To compile it as a module, choose M here. If unsure, say N. |
f3389805e [NETFILTER]: x_ta... |
983 984 |
config NETFILTER_XT_MATCH_STATISTIC tristate '"statistic" match support' |
33b8e7760 [NETFILTER]: Add ... |
985 |
depends on NETFILTER_ADVANCED |
f3389805e [NETFILTER]: x_ta... |
986 |
help |
68c1692e3 [NETFILTER]: stat... |
987 988 989 990 |
This option adds a `statistic' match, which allows you to match on packets periodically or randomly with a given percentage. To compile it as a module, choose M here. If unsure, say N. |
f3389805e [NETFILTER]: x_ta... |
991 |
|
2e4e6a17a [NETFILTER] x_tab... |
992 993 |
config NETFILTER_XT_MATCH_STRING tristate '"string" match support' |
33b8e7760 [NETFILTER]: Add ... |
994 |
depends on NETFILTER_ADVANCED |
2e4e6a17a [NETFILTER] x_tab... |
995 996 997 998 999 1000 1001 1002 1003 1004 1005 1006 |
select TEXTSEARCH select TEXTSEARCH_KMP select TEXTSEARCH_BM select TEXTSEARCH_FSM help This option adds a `string' match, which allows you to look for pattern matchings in packets. To compile it as a module, choose M here. If unsure, say N. config NETFILTER_XT_MATCH_TCPMSS tristate '"tcpmss" match support' |
33b8e7760 [NETFILTER]: Add ... |
1007 |
depends on NETFILTER_ADVANCED |
2e4e6a17a [NETFILTER] x_tab... |
1008 1009 1010 1011 1012 1013 |
help This option adds a `tcpmss' match, which allows you to examine the MSS value of TCP SYN packets, which control the maximum packet size for that connection. To compile it as a module, choose M here. If unsure, say N. |
ee4411a1b [NETFILTER]: x_ta... |
1014 1015 |
config NETFILTER_XT_MATCH_TIME tristate '"time" match support' |
33b8e7760 [NETFILTER]: Add ... |
1016 |
depends on NETFILTER_ADVANCED |
ee4411a1b [NETFILTER]: x_ta... |
1017 1018 1019 1020 1021 1022 1023 1024 1025 1026 |
---help--- This option adds a "time" match, which allows you to match based on the packet arrival time (at the machine which netfilter is running) on) or departure time/date (for locally generated packets). If you say Y here, try `iptables -m time --help` for more information. If you want to compile it as a module, say M here. If unsure, say N. |
1b50b8a37 [NETFILTER]: Add ... |
1027 1028 |
config NETFILTER_XT_MATCH_U32 tristate '"u32" match support' |
33b8e7760 [NETFILTER]: Add ... |
1029 |
depends on NETFILTER_ADVANCED |
1b50b8a37 [NETFILTER]: Add ... |
1030 1031 1032 1033 1034 1035 1036 1037 1038 |
---help--- u32 allows you to extract quantities of up to 4 bytes from a packet, AND them with specified masks, shift them by specified amounts and test whether the results are in any of a set of specified ranges. The specification of what to extract is general enough to skip over headers with lengths stored in the packet, as in IP or TCP header lengths. Details and examples are in the kernel module source. |
c2df73de2 netfilter: xtable... |
1039 |
endif # NETFILTER_XTABLES |
a6c1cd572 [NETFILTER] Fix K... |
1040 |
|
c2df73de2 netfilter: xtable... |
1041 |
endmenu |
a6c1cd572 [NETFILTER] Fix K... |
1042 |
|
a7b4f989a netfilter: ipset:... |
1043 |
source "net/netfilter/ipset/Kconfig" |
cb7f6a7b7 IPVS: Move IPVS t... |
1044 |
source "net/netfilter/ipvs/Kconfig" |