Message ID | 20200519230822.15290-1-phil@nwl.cc |
---|---|
State | Accepted |
Delegated to: | Pablo Neira |
Headers | show |
Series | [iptables] doc: libxt_MARK: OUTPUT chain is fine, too | expand |
On Wed, May 20, 2020 at 01:08:22AM +0200, Phil Sutter wrote: > In order to route packets originating from the host itself based on > fwmark, mangle table's OUTPUT chain must be used. Mention this chain as > alternative to PREROUTING. > > Fixes: c9be7f153f7bf ("doc: libxt_MARK: no longer restricted to mangle table") > Signed-off-by: Phil Sutter <phil@nwl.cc> > --- > extensions/libxt_MARK.man | 4 ++-- > 1 file changed, 2 insertions(+), 2 deletions(-) > > diff --git a/extensions/libxt_MARK.man b/extensions/libxt_MARK.man > index 712fb76f7340c..b2408597e98f1 100644 > --- a/extensions/libxt_MARK.man > +++ b/extensions/libxt_MARK.man > @@ -1,7 +1,7 @@ > This target is used to set the Netfilter mark value associated with the packet. > It can, for example, be used in conjunction with routing based on fwmark (needs > -iproute2). If you plan on doing so, note that the mark needs to be set in the > -PREROUTING chain of the mangle table to affect routing. > +iproute2). If you plan on doing so, note that the mark needs to be set in > +either the PREROUTING or the OUTPUT chain of the mangle table to affect routing. You have two choices: * Set the mark in filter OUTPUT chain => it does not affect routing. * Set the mark in the mangle OUTPUT chain => it _does_ affect routing. Are we on the same page?
On Tue, May 26, 2020 at 07:00:50PM +0200, Pablo Neira Ayuso wrote: > On Wed, May 20, 2020 at 01:08:22AM +0200, Phil Sutter wrote: > > In order to route packets originating from the host itself based on > > fwmark, mangle table's OUTPUT chain must be used. Mention this chain as > > alternative to PREROUTING. > > > > Fixes: c9be7f153f7bf ("doc: libxt_MARK: no longer restricted to mangle table") > > Signed-off-by: Phil Sutter <phil@nwl.cc> > > --- > > extensions/libxt_MARK.man | 4 ++-- > > 1 file changed, 2 insertions(+), 2 deletions(-) > > > > diff --git a/extensions/libxt_MARK.man b/extensions/libxt_MARK.man > > index 712fb76f7340c..b2408597e98f1 100644 > > --- a/extensions/libxt_MARK.man > > +++ b/extensions/libxt_MARK.man > > @@ -1,7 +1,7 @@ > > This target is used to set the Netfilter mark value associated with the packet. > > It can, for example, be used in conjunction with routing based on fwmark (needs > > -iproute2). If you plan on doing so, note that the mark needs to be set in the > > -PREROUTING chain of the mangle table to affect routing. > > +iproute2). If you plan on doing so, note that the mark needs to be set in > > +either the PREROUTING or the OUTPUT chain of the mangle table to affect routing. > > You have two choices: > > * Set the mark in filter OUTPUT chain => it does not affect routing. > * Set the mark in the mangle OUTPUT chain => it _does_ affect routing. > > Are we on the same page? Ah, I right I just re-read and it looks fine.
On Tue, May 26, 2020 at 07:05:31PM +0200, Pablo Neira Ayuso wrote: > On Tue, May 26, 2020 at 07:00:50PM +0200, Pablo Neira Ayuso wrote: > > On Wed, May 20, 2020 at 01:08:22AM +0200, Phil Sutter wrote: > > > In order to route packets originating from the host itself based on > > > fwmark, mangle table's OUTPUT chain must be used. Mention this chain as > > > alternative to PREROUTING. > > > > > > Fixes: c9be7f153f7bf ("doc: libxt_MARK: no longer restricted to mangle table") > > > Signed-off-by: Phil Sutter <phil@nwl.cc> > > > --- > > > extensions/libxt_MARK.man | 4 ++-- > > > 1 file changed, 2 insertions(+), 2 deletions(-) > > > > > > diff --git a/extensions/libxt_MARK.man b/extensions/libxt_MARK.man > > > index 712fb76f7340c..b2408597e98f1 100644 > > > --- a/extensions/libxt_MARK.man > > > +++ b/extensions/libxt_MARK.man > > > @@ -1,7 +1,7 @@ > > > This target is used to set the Netfilter mark value associated with the packet. > > > It can, for example, be used in conjunction with routing based on fwmark (needs > > > -iproute2). If you plan on doing so, note that the mark needs to be set in the > > > -PREROUTING chain of the mangle table to affect routing. > > > +iproute2). If you plan on doing so, note that the mark needs to be set in > > > +either the PREROUTING or the OUTPUT chain of the mangle table to affect routing. > > > > You have two choices: > > > > * Set the mark in filter OUTPUT chain => it does not affect routing. > > * Set the mark in the mangle OUTPUT chain => it _does_ affect routing. > > > > Are we on the same page? > > Ah, I right I just re-read and it looks fine. OK. :) Thanks, Phil
diff --git a/extensions/libxt_MARK.man b/extensions/libxt_MARK.man index 712fb76f7340c..b2408597e98f1 100644 --- a/extensions/libxt_MARK.man +++ b/extensions/libxt_MARK.man @@ -1,7 +1,7 @@ This target is used to set the Netfilter mark value associated with the packet. It can, for example, be used in conjunction with routing based on fwmark (needs -iproute2). If you plan on doing so, note that the mark needs to be set in the -PREROUTING chain of the mangle table to affect routing. +iproute2). If you plan on doing so, note that the mark needs to be set in +either the PREROUTING or the OUTPUT chain of the mangle table to affect routing. The mark field is 32 bits wide. .TP \fB\-\-set\-xmark\fP \fIvalue\fP[\fB/\fP\fImask\fP]
In order to route packets originating from the host itself based on fwmark, mangle table's OUTPUT chain must be used. Mention this chain as alternative to PREROUTING. Fixes: c9be7f153f7bf ("doc: libxt_MARK: no longer restricted to mangle table") Signed-off-by: Phil Sutter <phil@nwl.cc> --- extensions/libxt_MARK.man | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-)