diff options
author | Florian Westphal <fw@strlen.de> | 2017-07-07 13:29:03 +0200 |
---|---|---|
committer | Pablo Neira Ayuso <pablo@netfilter.org> | 2017-07-17 17:02:44 +0200 |
commit | 974292defee033bc43ccfcb2fcefc3eba3905340 (patch) | |
tree | f9865fb83ea6979a8f7ef02d10020af01090e3bb /net | |
parent | 97772bcd56efa21d9d8976db6f205574ea602f51 (diff) | |
download | op-kernel-dev-974292defee033bc43ccfcb2fcefc3eba3905340.zip op-kernel-dev-974292defee033bc43ccfcb2fcefc3eba3905340.tar.gz |
netfilter: nf_tables: only allow in/output for arp packets
arp packets cannot be forwarded.
They can be bridged, but then they can be filtered using
either ebtables or nftables bridge family.
The bridge netfilter exposes a "call-arptables" switch which
pushes packets into arptables, but lets not expose this for nftables, so better
close this asap.
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'net')
-rw-r--r-- | net/ipv4/netfilter/nf_tables_arp.c | 3 |
1 files changed, 1 insertions, 2 deletions
diff --git a/net/ipv4/netfilter/nf_tables_arp.c b/net/ipv4/netfilter/nf_tables_arp.c index 805c8dd..4bbc273 100644 --- a/net/ipv4/netfilter/nf_tables_arp.c +++ b/net/ipv4/netfilter/nf_tables_arp.c @@ -72,8 +72,7 @@ static const struct nf_chain_type filter_arp = { .family = NFPROTO_ARP, .owner = THIS_MODULE, .hook_mask = (1 << NF_ARP_IN) | - (1 << NF_ARP_OUT) | - (1 << NF_ARP_FORWARD), + (1 << NF_ARP_OUT), }; static int __init nf_tables_arp_init(void) |