diff mbox series

[iptables] extensions: libip6t_mh: fix bogus translation error

Message ID 20181119131005.9431-1-pablo@netfilter.org
State Accepted
Delegated to: Pablo Neira
Headers show
Series [iptables] extensions: libip6t_mh: fix bogus translation error | expand

Commit Message

Pablo Neira Ayuso Nov. 19, 2018, 1:10 p.m. UTC
libip6t_mh.txlate: Fail
 src: ip6tables-translate -A INPUT -p mh --mh-type 1 -j ACCEPT
 exp: nft add rule ip6 filter INPUT meta l4proto 135 mh type 1 counter accept
 res: nft add rule ip6 filter INPUT meta l4proto mobility-header mh type 1 counter accept

Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
---
 extensions/libip6t_mh.txlate | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)
diff mbox series

Patch

diff --git a/extensions/libip6t_mh.txlate b/extensions/libip6t_mh.txlate
index ccc07c3d5ecb..f5d638c09ca8 100644
--- a/extensions/libip6t_mh.txlate
+++ b/extensions/libip6t_mh.txlate
@@ -1,5 +1,5 @@ 
 ip6tables-translate -A INPUT -p mh --mh-type 1 -j ACCEPT
-nft add rule ip6 filter INPUT meta l4proto 135 mh type 1 counter accept
+nft add rule ip6 filter INPUT meta l4proto mobility-header mh type 1 counter accept
 
 ip6tables-translate -A INPUT -p mh --mh-type 1:3 -j ACCEPT
-nft add rule ip6 filter INPUT meta l4proto 135 mh type 1-3 counter accept
+nft add rule ip6 filter INPUT meta l4proto mobility-header mh type 1-3 counter accept