]> git.ipfire.org Git - thirdparty/iptables.git/commit
extensions: libxt_conntrack: simplify translation using negation
authorPablo Neira Ayuso <pablo@netfilter.org>
Wed, 2 Jun 2021 23:58:43 +0000 (01:58 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Mon, 7 Jun 2021 19:35:27 +0000 (21:35 +0200)
commitc8145139cb230ff22837795c97f2e264c574c64c
treeaf4a98ee8f9ea7ad3702c572751af920ba515c04
parent1c934617f661dc0bc471c0f0b4ace254c55182df
extensions: libxt_conntrack: simplify translation using negation

Available since nftables 0.9.9. For example:

 # iptables-translate -I INPUT -m state ! --state NEW,INVALID
 nft insert rule ip filter INPUT ct state ! invalid,new  counter

Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
extensions/libxt_conntrack.c
extensions/libxt_conntrack.txlate