ip6tables -m state (match state) not working...

Jay Cliburn jacliburn at bellsouth.net
Mon Oct 9 01:09:10 UTC 2006


Michael H. Warfield wrote:
> On Sun, 2006-10-08 at 13:32 -0500, Jay Cliburn wrote:
>> Michael H. Warfield wrote:
>>> Hey all,
>>>
>>> 	I've found that the IPv6 state matching is non-functional in FC6.  
> 
>> Oh, and by the way, ip6tables state matching is nonfunctional, period; not just 
>> in Fedora.  The Netfilter team hasn't yet implemented state matching in ip6tables.
> 
> 	Strange that it accepts the -m state option to ip6tables then.  There
> is certainly an libip6t_state.so in /lib/iptables.  If it hasn't been
> implemented, then what's in that friggen library?

Hmmm...  You prompted me to look.  From netfilter.org:


Main Features

     * stateless packet filtering (IPv4 and IPv6)
     * stateful packet filtering (IPv4 and IPv6)

This is new.




More information about the fedora-test-list mailing list