[pve-devel] [PATCH] add ips feature v5

Dietmar Maurer dietmar at proxmox.com
Wed Mar 19 19:34:31 CET 2014


> in this case:
> 
> tap1-out : ACCEPT (ips off)   -----> tap2-in : ACCEPT (ips on)
> 
> 
> We don't want always NFQUEUE  in tap1-out, because ips is off, but we want
> NFQUEUE if the destination have ips on.

I do not understand this. In tap-out we simply set the mark (we do not jump to ACCEPT there),
so why is that a problem?


More information about the pve-devel mailing list