[Bug 904] Matching ah without optional argument gives unintuitive result

bugzilla-daemon at netfilter.org bugzilla-daemon at netfilter.org
Tue Feb 18 08:41:38 CET 2014


--- Comment #3 from Sebastian <saltyacid at gmail.com> 2014-02-18 08:41:37 CET ---
Thank you for your comments!

However, for IPv6 -p ah does not work:

 "-p" uses the first non-extension header (which can never
be AH for IPv6) while "-m ah" matches on AH extension headers.

ip6tables even say so, as using -p ah gives the following warning:
"Warning: never matched protocol: ah. use extension match instead"

So I still think this needs to be explained somewhere - for example when using
the rule.

Configure bugmail: https://bugzilla.netfilter.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are watching all bug changes.

More information about the netfilter-buglog mailing list