tcp sport 1024 tcp dport 22;ok
tcp sport 1024 tcp dport 22 tcp sequence 0;ok
-tcp sequence 0 tcp sport 1024 tcp dport 22;ok
+tcp sequence 0 tcp sport 1024 tcp dport 22;ok;tcp sport 1024 tcp dport 22 tcp sequence 0
tcp sequence 0 tcp sport { 1024, 1022} tcp dport 22;ok
tcp sequence 22;ok
*ip6;test-ip6
:prerouting;type nat hook prerouting priority 0
-tcp dport 80-90 dnat 2001:838:35f:1::-2001:838:35f:2:: :80-100;ok
-tcp dport 80-90 dnat 2001:838:35f:1::-2001:838:35f:2:: :100;ok
+tcp dport 80-90 dnat 2001:838:35f:1::-2001:838:35f:2:::80-100;ok
+tcp dport 80-90 dnat 2001:838:35f:1::-2001:838:35f:2:: :100;ok;tcp dport 80-90 dnat 2001:838:35f:1::-2001:838:35f:2:::100
-*ip6;test-ip4
+*ip6;test-ip6
# BUG: There is a bug with icmpv6 and inet tables
- *inet;test-inet
:input;type filter hook input priority 0
- icmpv6 type != {mld-listener-query, time-exceeded, nd-router-advert} accept;ok
icmpv6 code 4;ok
-icmpv6 code 3-66;ok;icmpv6 code >= 3 icmpv6 code <= 66
+icmpv6 code 3-66;ok
icmpv6 code {5, 6, 7} accept;ok
- icmpv6 code != {3, 66, 34};ok
icmpv6 code { 3-66};ok
icmpv6 checksum 2222 log;ok
icmpv6 checksum != 2222 log;ok
-icmpv6 checksum 222-226;ok;icmpv6 checksum >= 222 icmpv6 checksum <= 226
+icmpv6 checksum 222-226;ok
icmpv6 checksum != 2222 log;ok
icmpv6 checksum { 222, 226};ok
- icmpv6 checksum != { 222, 226};ok
icmpv6 sequence {2, 4};ok
- icmpv6 sequence != {2, 4};ok
-icmpv6 sequence 2-4;ok;icmpv6 sequence >= 2 icmpv6 sequence <= 4
-icmpv6 sequence != 2-4;ok;icmpv6 sequence < 2 icmpv6 sequence > 4
+icmpv6 sequence 2-4;ok
+icmpv6 sequence != 2-4;ok
icmpv6 sequence { 2-4};ok
- icmpv6 sequence != {2-4};ok
- *inet;test-inet
:postrouting;type nat hook postrouting priority 0
-tcp dport 80-90 snat 2001:838:35f:1::-2001:838:35f:2:: :80-100;ok
-tcp dport 80-90 snat 2001:838:35f:1::-2001:838:35f:2:: :100;ok
+tcp dport 80-90 snat 2001:838:35f:1::-2001:838:35f:2:: :80-100;ok;tcp dport 80-90 snat 2001:838:35f:1::-2001:838:35f:2:::80-100
+tcp dport 80-90 snat 2001:838:35f:1::-2001:838:35f:2:::100;ok
warning += 1
print_differences_warning(filename, lineno,
- rule[0], rule_output,
+ teoric_exit.rstrip(), rule_output,
cmd)
if not force_all_family_option: