Re: [nf-next] netfilter: Add support for inner IPv6 packet match

2019-01-05 Thread David R. Bild
On Jan 25, 2018 at 08:13:00PM, Pabel wrote: > On Thu, Jan 18, 2018 at 04:13:25PM +0100, Ahmed Abdelsalam wrote: > [...] > > diff --git a/include/uapi/linux/netfilter_ipv6/ip6t_inner6.h > > b/include/uapi/linux/netfilter_ipv6/ip6t_inner6.h > > new file mode 100644 > > index 000..7017fa4 > > ---

Re: [nf-next] netfilter: Add support for inner IPv6 packet match

2018-01-26 Thread Ahmed Abdelsalam
Hi Pablo, > Hi Ahmed, > > On Thu, Jan 18, 2018 at 04:13:25PM +0100, Ahmed Abdelsalam wrote: > [...] > > diff --git a/include/uapi/linux/netfilter_ipv6/ip6t_inner6.h > > b/include/uapi/linux/netfilter_ipv6/ip6t_inner6.h > Matching at inner headers is a very useful, no doubt. Problem is that > th

Re: [nf-next] netfilter: Add support for inner IPv6 packet match

2018-01-25 Thread Pablo Neira Ayuso
Hi Ahmed, On Thu, Jan 18, 2018 at 04:13:25PM +0100, Ahmed Abdelsalam wrote: [...] > diff --git a/include/uapi/linux/netfilter_ipv6/ip6t_inner6.h > b/include/uapi/linux/netfilter_ipv6/ip6t_inner6.h > new file mode 100644 > index 000..7017fa4 > --- /dev/null > +++ b/include/uapi/linux/netfilter

[nf-next] netfilter: Add support for inner IPv6 packet match

2018-01-18 Thread Ahmed Abdelsalam
As described in the SRv6 network programming document [1], the SRv6 information can be added to a packet in two different modes, insert or encap. As shown below, you can see the original IPv6 packet and how it is carried in the two different encapsulation modes. In the insert mode the SRH header