LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices

Reply
 
LinkBack Search this Thread
Old 11-23-2009, 03:45 PM   #1
rhine2
LQ Newbie
 
Registered: Mar 2009
Posts: 16

Rep: Reputation: 0
conntrack and connmark


I am little confused with Netfilter marks and iptables CONNMARK. Please help clear the understanding.

example:
iptables -t mangle -A mychain -j CONNMARK --restore-mark --mask 0xff
iptables -t mangle -A mychain -m connmark !--mark 0/0xff00 -j RETURN

The first one is CONNMARK target is trying to restore the "mark" made by what? Is it connection tracking? But markings are not done at ip_conntrack is it? packet marking is done at the iptables - right? I am confused

Also, the second one in the rule, it is trying to match a mark if it is non-zero and if there is a match it returns? Please help untangle my misunderstanding.
 
Old 11-23-2009, 04:28 PM   #2
nimnull22
Senior Member
 
Registered: Jul 2009
Distribution: OpenSuse 11.1, Fedora 14
Posts: 1,554

Rep: Reputation: 89
May be that http://www.frozentux.net/documents/iptables-tutorial/, helps you.
 
Old 11-23-2009, 09:59 PM   #3
rhine2
LQ Newbie
 
Registered: Mar 2009
Posts: 16

Original Poster
Rep: Reputation: 0
Quote:
Originally Posted by nimnull22 View Post
Not really. Doesn't explain what I want.
 
Old 11-23-2009, 10:37 PM   #4
nimnull22
Senior Member
 
Registered: Jul 2009
Distribution: OpenSuse 11.1, Fedora 14
Posts: 1,554

Rep: Reputation: 89
I don't know but, if you prefer I show you:

Option: --restore-mark
Explanation: This target option restores the packet mark from the connection mark as defined by the CONNMARK.

English is not my native language, but I understood.
 
Old 11-23-2009, 11:02 PM   #5
rhine2
LQ Newbie
 
Registered: Mar 2009
Posts: 16

Original Poster
Rep: Reputation: 0
You didn't read/understand properly what I am asking. I am asking what is this "mark" it is trying to restore? Where is this mark come from? What process puts the mark on the packet? What is the basis of this mark?
 
Old 11-24-2009, 11:39 PM   #6
rhine2
LQ Newbie
 
Registered: Mar 2009
Posts: 16

Original Poster
Rep: Reputation: 0
No one knows the answer? Strange!
 
Old 11-25-2009, 08:05 AM   #7
landysaccount
Member
 
Registered: Sep 2008
Location: Dominican Republic
Distribution: Debian Lenny
Posts: 160

Rep: Reputation: 16
Post your entire script so we can take a look at it.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
IPTables/Conntrack MikeQ Linux - Server 1 08-04-2009 02:02 PM
iptables connmark and mark match problem sodoojin Linux - Newbie 0 02-19-2009 02:44 PM
Question on copying iptables CONNMARK to netfilter MARK Praetorian Linux - Networking 4 06-19-2008 08:24 AM
need connmark Sushy Slackware 3 10-19-2005 02:14 PM
Need connmark feature Sushy Linux - Networking 1 10-19-2005 02:07 PM


All times are GMT -5. The time now is 10:56 AM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration