X-Git-Url: http://git.onelab.eu/?a=blobdiff_plain;f=extensions%2Flibipt_set.man;fp=extensions%2Flibipt_set.man;h=d280577d9f4e409f3c0cfbb0a0be6ac01010b178;hb=6afea0b41dfbc3824956d11d960ad80097218feb;hp=0000000000000000000000000000000000000000;hpb=f7b70cf9e00324b89b02de213bcd0dde7044d035;p=iptables.git diff --git a/extensions/libipt_set.man b/extensions/libipt_set.man new file mode 100644 index 0000000..d280577 --- /dev/null +++ b/extensions/libipt_set.man @@ -0,0 +1,17 @@ +This modules macthes IP sets which can be defined by ipset(8). +.TP +.BR "--set " "setname flag[,flag...]" +where flags are +.BR "src" +and/or +.BR "dst" +and there can be no more than six of them. Hence the command +.nf + iptables -A FORWARD -m set --set test src,dst +.fi +will match packets, for which (depending on the type of the set) the source +address or port number of the packet can be found in the specified set. If +there is a binding belonging to the mached set element or there is a default +binding for the given set, then the rule will match the packet only if +additionally (depending on the type of the set) the destination address or +port number of the packet can be found in the set according to the binding.