-
- Downloads
netfilter: nf_conntrack: split up IPCT_STATUS event
Split up the IPCT_STATUS event into an IPCT_REPLY event, which is generated
when the IPS_SEEN_REPLY bit is set, and an IPCT_ASSURED event, which is
generated when the IPS_ASSURED bit is set.
In combination with a following patch to support selective event delivery,
this can be used for "sparse" conntrack replication: start replicating the
conntrack entry after it reached the ASSURED state and that way it's SYN-flood
resistant.
Signed-off-by:
Patrick McHardy <kaber@trash.net>
Showing
- include/net/netfilter/nf_conntrack_ecache.h 11 additions, 10 deletionsinclude/net/netfilter/nf_conntrack_ecache.h
- net/netfilter/nf_conntrack_core.c 1 addition, 1 deletionnet/netfilter/nf_conntrack_core.c
- net/netfilter/nf_conntrack_netlink.c 4 additions, 2 deletionsnet/netfilter/nf_conntrack_netlink.c
- net/netfilter/nf_conntrack_proto_gre.c 1 addition, 1 deletionnet/netfilter/nf_conntrack_proto_gre.c
- net/netfilter/nf_conntrack_proto_sctp.c 1 addition, 1 deletionnet/netfilter/nf_conntrack_proto_sctp.c
- net/netfilter/nf_conntrack_proto_tcp.c 1 addition, 1 deletionnet/netfilter/nf_conntrack_proto_tcp.c
- net/netfilter/nf_conntrack_proto_udp.c 1 addition, 1 deletionnet/netfilter/nf_conntrack_proto_udp.c
- net/netfilter/nf_conntrack_proto_udplite.c 1 addition, 1 deletionnet/netfilter/nf_conntrack_proto_udplite.c
Loading
Please sign in to comment