diff options
| author | Alexey Dobriyan <adobriyan@sw.ru> | 2008-01-31 07:04:13 -0500 |
|---|---|---|
| committer | David S. Miller <davem@davemloft.net> | 2008-01-31 22:27:39 -0500 |
| commit | 8280aa6182f03c4e27dc235ce0440bc94927dc28 (patch) | |
| tree | aff3a05fabf07b8bb17d0e0867a48fdcf4921045 /include/net | |
| parent | 336b517fdc0f92f54a3f77a2d0933f9556aa79ad (diff) | |
[NETFILTER]: ip6_tables: per-netns IPv6 FILTER, MANGLE, RAW
Now it's possible to list and manipulate per-netns ip6tables rules.
Filtering decisions are based on init_net's table so far.
P.S.: remove init_net check in inet6_create() to see the effect
Signed-off-by: Alexey Dobriyan <adobriyan@sw.ru>
Signed-off-by: Patrick McHardy <kaber@trash.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'include/net')
| -rw-r--r-- | include/net/netns/ipv6.h | 5 |
1 files changed, 5 insertions, 0 deletions
diff --git a/include/net/netns/ipv6.h b/include/net/netns/ipv6.h index 187c4248df22..1dd7de4e4195 100644 --- a/include/net/netns/ipv6.h +++ b/include/net/netns/ipv6.h | |||
| @@ -31,5 +31,10 @@ struct netns_ipv6 { | |||
| 31 | struct ipv6_devconf *devconf_all; | 31 | struct ipv6_devconf *devconf_all; |
| 32 | struct ipv6_devconf *devconf_dflt; | 32 | struct ipv6_devconf *devconf_dflt; |
| 33 | struct netns_frags frags; | 33 | struct netns_frags frags; |
| 34 | #ifdef CONFIG_NETFILTER | ||
| 35 | struct xt_table *ip6table_filter; | ||
| 36 | struct xt_table *ip6table_mangle; | ||
| 37 | struct xt_table *ip6table_raw; | ||
| 38 | #endif | ||
| 34 | }; | 39 | }; |
| 35 | #endif | 40 | #endif |
