[Bug 640] ipset-4.2 : ipset -T <some_setlist> <address> always negative

bugzilla-daemon at bugzilla.netfilter.org bugzilla-daemon at bugzilla.netfilter.org
Fri Mar 12 14:53:08 CET 2010


http://bugzilla.netfilter.org/show_bug.cgi?id=640





------- Comment #1 from brendlerjg at gmail.com  2010-03-12 14:53 -------
After some additional testing, I have concluded that the setlist does indeed
work, with respect to iptables/netfilter.  It is merely testing from within
ipset that does not work.

One of two things should happen:

a) the portion of the man page that documents "setlist" should make it known
that ipset -T can only be used to test the inclusion of ipsets within a setlist
(and cannot be used to test the inclusion of an ipset member); or

b) the ipset -T function should be extended to mirror the behavior of iptables
setlist matches (as it mirrors this behavior for the other ipset types).

Thank you for the excellent tool.


-- 
Configure bugmail: http://bugzilla.netfilter.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.



More information about the netfilter-buglog mailing list