Re: [PATCH RFC] src: support for arp ether and IP source and destination fields

2018-12-07 Thread Pablo Neira Ayuso
On Fri, Dec 07, 2018 at 02:05:15PM +0100, Florian Westphal wrote: > Pablo Neira Ayuso wrote: > > Add ip-saddr, ip-daddr, ether-saddr, ether-daddr for arp, eg. > > > > # nft add table arp x > > # nft add chain arp x y { type filter hook input priority 0\; } > > # nft add rule arp x y arp

Re: [PATCH RFC] src: support for arp ether and IP source and destination fields

2018-12-07 Thread Florian Westphal
Pablo Neira Ayuso wrote: > Add ip-saddr, ip-daddr, ether-saddr, ether-daddr for arp, eg. > > # nft add table arp x > # nft add chain arp x y { type filter hook input priority 0\; } > # nft add rule arp x y arp ip-saddr 192.168.2.1 counter 'arp {ip,ether} {s,d}addr' would create ambiguities?

[PATCH RFC] src: support for arp ether and IP source and destination fields

2018-12-07 Thread Pablo Neira Ayuso
Add ip-saddr, ip-daddr, ether-saddr, ether-daddr for arp, eg. # nft add table arp x # nft add chain arp x y { type filter hook input priority 0\; } # nft add rule arp x y arp ip-saddr 192.168.2.1 counter Testing this: # ip neigh flush dev eth0 # ping 8.8.8.8 # nft list ruleset table arp