On Fri, 16 Nov 2018 07:27:36 +0300 Reco <recovery...@enotuniq.net> wrote:
... > kernel can mark any outgoing packet. > These 'marks' are not actual modification of packet (hence they are > invisible once packet goes into NIC), but rather a way to apply a > pre-determined set of rules to it. > net_cls controller is a way to apply such mark to any and all outgoing > packet generated by a group of processes. ... Thanks for the explanations. Celejar