1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31
|
#!/bin/bash
# NFT_TEST_REQUIRES(NFT_TEST_HAVE_synproxy)
# * creating valid named objects
# * referencing them from a valid rule
RULESET="
table inet x {
synproxy https-synproxy {
mss 1460
wscale 7
timestamp sack-perm
}
synproxy other-synproxy {
mss 1460
wscale 5
}
map test2 {
type ipv4_addr : synproxy
flags interval
elements = { 192.168.1.0/24 : "https-synproxy", 192.168.2.0/24 : "other-synproxy" }
}
chain y {
type filter hook input priority 0; policy accept;
synproxy name ip saddr map { 192.168.1.0/24 : "https-synproxy", 192.168.2.0/24 : "other-synproxy" }
}
}"
set -e
$NFT -f - <<< "$RULESET"
|