Hi Florian & Pablo,
Thank your very much for your quick feedback.
On 02/16/2018 12:28 PM, Pablo Neira Ayuso wrote:
On Fri, Feb 16, 2018 at 12:07:06PM +0100, Florian Westphal wrote:
Gregory Vander Schueren wrote:
[ cc netdev ]
If sysctl bridge-nf-call-iptables is enabled, iptables chains ar
On Fri, Feb 16, 2018 at 12:07:06PM +0100, Florian Westphal wrote:
> Gregory Vander Schueren wrote:
>
> [ cc netdev ]
>
> > If sysctl bridge-nf-call-iptables is enabled, iptables chains are already
> > traversed from the bridging code. In such case, tproxy already happened when
> > reaching ip_rc
Gregory Vander Schueren wrote:
[ cc netdev ]
> If sysctl bridge-nf-call-iptables is enabled, iptables chains are already
> traversed from the bridging code. In such case, tproxy already happened when
> reaching ip_rcv. Thus no need to call skb_orphan as this would actually undo
> tproxy.
I don'