Okay but...
Before God I sware that NF_ACCEPT
did not work that way in the past and
I had to have a -j ACCEPT after my -j QUEUE.
I am right now looking at the code and
packing I did containing these comments
and also remembering clearly receiving
instruction, I believe, from the person
who wrote the Perl/lib_ipq examples that
it worked the way I'm describing...
I'll stand corrected, but point out that
if it doesn't do like you'd expect, try
it my way.
-AEF
On Thu, 2002-01-03 at 19:16, Ian Jones wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Allen Francom <[EMAIL PROTECTED]> writes:
>
> > Um... no...
> >
> > If your default table policy is DROP then
> > libipq ACCEPT does not equal -j ACCEPT...
> >
> > At least, that's not the way it used to be...
>
> ???
> huh?
>
> If you QUEUE and then call ipq_set_verdict in userspace with a
> parameter of NF_ACCEPT you will be accepting it. The table policy will
> never be an issue inside userspace because the packet will never
> complete the chain. Always been that way AFAIK.
>
> -----BEGIN PGP SIGNATURE-----
> Comment: Keeping the world safe for geeks.
>
> iD8DBQE8NK3/wBVKl/Nci0oRArEwAKD+OCRguxyvAVEnkENKSU5ydHM6wgCg36fc
> SRTpA0uFDSPYbBSGZo7/jac=
> =UocL
> -----END PGP SIGNATURE-----
>
_______________________________________________
Bridge mailing list
[EMAIL PROTECTED]
http://www.math.leidenuniv.nl/mailman/listinfo/bridge