1ec8f24b7SThomas Gleixner# SPDX-License-Identifier: GPL-2.0-only 29fb9cbb1SYasuyuki Kozakaimenu "Core Netfilter Configuration" 3864e898bSMasahiro Yamada depends on INET && NETFILTER 49fb9cbb1SYasuyuki Kozakai 5e687ad60SPablo Neiraconfig NETFILTER_INGRESS 6e687ad60SPablo Neira bool "Netfilter ingress support" 7529985deSPablo Neira Ayuso default y 8e687ad60SPablo Neira select NET_INGRESS 9e687ad60SPablo Neira help 10e687ad60SPablo Neira This allows you to classify packets from ingress using the Netfilter 11e687ad60SPablo Neira infrastructure. 12e687ad60SPablo Neira 1342df6e1dSLukas Wunnerconfig NETFILTER_EGRESS 1442df6e1dSLukas Wunner bool "Netfilter egress support" 1542df6e1dSLukas Wunner default y 1642df6e1dSLukas Wunner select NET_EGRESS 1742df6e1dSLukas Wunner help 1842df6e1dSLukas Wunner This allows you to classify packets before transmission using the 1942df6e1dSLukas Wunner Netfilter infrastructure. 2042df6e1dSLukas Wunner 2142df6e1dSLukas Wunnerconfig NETFILTER_SKIP_EGRESS 2242df6e1dSLukas Wunner def_bool NETFILTER_EGRESS && (NET_CLS_ACT || IFB) 2342df6e1dSLukas Wunner 24f9e815b3SHarald Welteconfig NETFILTER_NETLINK 25d4349ba9SPablo Neira Ayuso bool 267af4cc3fSHarald Welte 272a95183aSFlorian Westphalconfig NETFILTER_FAMILY_BRIDGE 282a95183aSFlorian Westphal bool 292a95183aSFlorian Westphal 302a95183aSFlorian Westphalconfig NETFILTER_FAMILY_ARP 312a95183aSFlorian Westphal bool 322a95183aSFlorian Westphal 3384601d6eSFlorian Westphalconfig NETFILTER_BPF_LINK 3484601d6eSFlorian Westphal def_bool BPF_SYSCALL 3584601d6eSFlorian Westphal 36e2cf17d3SFlorian Westphalconfig NETFILTER_NETLINK_HOOK 37e2cf17d3SFlorian Westphal tristate "Netfilter base hook dump support" 38e2cf17d3SFlorian Westphal depends on NETFILTER_ADVANCED 39d4fb1f95SFlorian Westphal depends on NF_TABLES 40e2cf17d3SFlorian Westphal select NETFILTER_NETLINK 41e2cf17d3SFlorian Westphal help 42e2cf17d3SFlorian Westphal If this option is enabled, the kernel will include support 43e2cf17d3SFlorian Westphal to list the base netfilter hooks via NFNETLINK. 44e2cf17d3SFlorian Westphal This is helpful for debugging. 45e2cf17d3SFlorian Westphal 4694139027SPablo Neira Ayusoconfig NETFILTER_NETLINK_ACCT 4794139027SPablo Neira Ayuso tristate "Netfilter NFACCT over NFNETLINK interface" 4894139027SPablo Neira Ayuso depends on NETFILTER_ADVANCED 4994139027SPablo Neira Ayuso select NETFILTER_NETLINK 5094139027SPablo Neira Ayuso help 5194139027SPablo Neira Ayuso If this option is enabled, the kernel will include support 5294139027SPablo Neira Ayuso for extended accounting via NFNETLINK. 5394139027SPablo Neira Ayuso 547af4cc3fSHarald Welteconfig NETFILTER_NETLINK_QUEUE 557af4cc3fSHarald Welte tristate "Netfilter NFQUEUE over NFNETLINK interface" 5633b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 572eeeba39SPatrick McHardy select NETFILTER_NETLINK 587af4cc3fSHarald Welte help 597af4cc3fSHarald Welte If this option is enabled, the kernel will include support 607af4cc3fSHarald Welte for queueing packets via NFNETLINK. 617af4cc3fSHarald Welte 620597f268SHarald Welteconfig NETFILTER_NETLINK_LOG 630597f268SHarald Welte tristate "Netfilter LOG over NFNETLINK interface" 6433b8e776SPatrick McHardy default m if NETFILTER_ADVANCED=n 652eeeba39SPatrick McHardy select NETFILTER_NETLINK 660597f268SHarald Welte help 670597f268SHarald Welte If this option is enabled, the kernel will include support 680597f268SHarald Welte for logging packets via NFNETLINK. 690597f268SHarald Welte 700597f268SHarald Welte This obsoletes the existing ipt_ULOG and ebg_ulog mechanisms, 710597f268SHarald Welte and is also scheduled to replace the old syslog-based ipt_LOG 720597f268SHarald Welte and ip6t_LOG modules. 730597f268SHarald Welte 74f6b7b5f4SFernando Fernandez Manceraconfig NETFILTER_NETLINK_OSF 75f6b7b5f4SFernando Fernandez Mancera tristate "Netfilter OSF over NFNETLINK interface" 76f6b7b5f4SFernando Fernandez Mancera depends on NETFILTER_ADVANCED 77f6b7b5f4SFernando Fernandez Mancera select NETFILTER_NETLINK 78f6b7b5f4SFernando Fernandez Mancera help 79f6b7b5f4SFernando Fernandez Mancera If this option is enabled, the kernel will include support 80f6b7b5f4SFernando Fernandez Mancera for passive OS fingerprint via NFNETLINK. 81f6b7b5f4SFernando Fernandez Mancera 82ab4f58c7SPatrick McHardyconfig NF_CONNTRACK 83b321e144SPatrick McHardy tristate "Netfilter connection tracking support" 8433b8e776SPatrick McHardy default m if NETFILTER_ADVANCED=n 85a0ae2562SFlorian Westphal select NF_DEFRAG_IPV4 86a0ae2562SFlorian Westphal select NF_DEFRAG_IPV6 if IPV6 != n 87b321e144SPatrick McHardy help 889fb9cbb1SYasuyuki Kozakai Connection tracking keeps a record of what packets have passed 899fb9cbb1SYasuyuki Kozakai through your machine, in order to figure out how they are related 909fb9cbb1SYasuyuki Kozakai into connections. 919fb9cbb1SYasuyuki Kozakai 92b321e144SPatrick McHardy This is required to do Masquerading or other kinds of Network 93b11c16beSRuss Dill Address Translation. It can also be used to enhance packet 94b11c16beSRuss Dill filtering (see `Connection state match support' below). 95b321e144SPatrick McHardy 96b321e144SPatrick McHardy To compile it as a module, choose M here. If unsure, say N. 97b321e144SPatrick McHardy 98db3187aeSFlorian Westphalconfig NF_LOG_SYSLOG 99db3187aeSFlorian Westphal tristate "Syslog packet logging" 100db3187aeSFlorian Westphal default m if NETFILTER_ADVANCED=n 101db3187aeSFlorian Westphal help 102db3187aeSFlorian Westphal This option enable support for packet logging via syslog. 103e465cccdSFlorian Westphal It supports IPv4, IPV6, ARP and common transport protocols such 104e465cccdSFlorian Westphal as TCP and UDP. 105db3187aeSFlorian Westphal This is a simpler but less flexible logging method compared to 106db3187aeSFlorian Westphal CONFIG_NETFILTER_NETLINK_LOG. 107db3187aeSFlorian Westphal If both are enabled the backend to use can be configured at run-time 108db3187aeSFlorian Westphal by means of per-address-family sysctl tunables. 109db3187aeSFlorian Westphal 110c2df73deSJan Engelhardtif NF_CONNTRACK 111625c5561SFlorian Westphalconfig NETFILTER_CONNCOUNT 112625c5561SFlorian Westphal tristate 113c2df73deSJan Engelhardt 1149fb9cbb1SYasuyuki Kozakaiconfig NF_CONNTRACK_MARK 1159fb9cbb1SYasuyuki Kozakai bool 'Connection mark tracking support' 11633b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 1179fb9cbb1SYasuyuki Kozakai help 1189fb9cbb1SYasuyuki Kozakai This option enables support for connection marks, used by the 1199fb9cbb1SYasuyuki Kozakai `CONNMARK' target and `connmark' match. Similar to the mark value 1209fb9cbb1SYasuyuki Kozakai of packets, but this mark value is kept in the conntrack session 1219fb9cbb1SYasuyuki Kozakai instead of the individual packets. 1229fb9cbb1SYasuyuki Kozakai 1237c9728c3SJames Morrisconfig NF_CONNTRACK_SECMARK 1247c9728c3SJames Morris bool 'Connection tracking security mark support' 125c2df73deSJan Engelhardt depends on NETWORK_SECMARK 12677076934SVegard Nossum default y if NETFILTER_ADVANCED=n 1277c9728c3SJames Morris help 1287c9728c3SJames Morris This option enables security markings to be applied to 1297c9728c3SJames Morris connections. Typically they are copied to connections from 1307c9728c3SJames Morris packets using the CONNSECMARK target and copied back from 1317c9728c3SJames Morris connections to packets with the same target, with the packets 1327c9728c3SJames Morris being originally labeled via SECMARK. 1337c9728c3SJames Morris 1347c9728c3SJames Morris If unsure, say 'N'. 1357c9728c3SJames Morris 1365d0aa2ccSPatrick McHardyconfig NF_CONNTRACK_ZONES 1375d0aa2ccSPatrick McHardy bool 'Connection tracking zones' 1385d0aa2ccSPatrick McHardy depends on NETFILTER_ADVANCED 1395d0aa2ccSPatrick McHardy help 1405d0aa2ccSPatrick McHardy This option enables support for connection tracking zones. 1415d0aa2ccSPatrick McHardy Normally, each connection needs to have a unique system wide 1425d0aa2ccSPatrick McHardy identity. Connection tracking zones allow to have multiple 1435d0aa2ccSPatrick McHardy connections using the same identity, as long as they are 1445d0aa2ccSPatrick McHardy contained in different zones. 1455d0aa2ccSPatrick McHardy 1465d0aa2ccSPatrick McHardy If unsure, say `N'. 1475d0aa2ccSPatrick McHardy 14854b07dcaSJan Engelhardtconfig NF_CONNTRACK_PROCFS 14954b07dcaSJan Engelhardt bool "Supply CT list in procfs (OBSOLETE)" 15054b07dcaSJan Engelhardt depends on PROC_FS 151a7f7f624SMasahiro Yamada help 15254b07dcaSJan Engelhardt This option enables for the list of known conntrack entries 15354b07dcaSJan Engelhardt to be shown in procfs under net/netfilter/nf_conntrack. This 15454b07dcaSJan Engelhardt is considered obsolete in favor of using the conntrack(8) 15554b07dcaSJan Engelhardt tool which uses Netlink. 15654b07dcaSJan Engelhardt 1579fb9cbb1SYasuyuki Kozakaiconfig NF_CONNTRACK_EVENTS 1588ce22fcaSPatrick McHardy bool "Connection tracking events" 15933b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 1609fb9cbb1SYasuyuki Kozakai help 1619fb9cbb1SYasuyuki Kozakai If this option is enabled, the connection tracking code will 1629fb9cbb1SYasuyuki Kozakai provide a notifier chain that can be used by other kernel code 1639fb9cbb1SYasuyuki Kozakai to get notified about changes in the connection tracking state. 1649fb9cbb1SYasuyuki Kozakai 1659fb9cbb1SYasuyuki Kozakai If unsure, say `N'. 1669fb9cbb1SYasuyuki Kozakai 167dd705072SPablo Neira Ayusoconfig NF_CONNTRACK_TIMEOUT 168dd705072SPablo Neira Ayuso bool 'Connection tracking timeout' 169dd705072SPablo Neira Ayuso depends on NETFILTER_ADVANCED 170dd705072SPablo Neira Ayuso help 171dd705072SPablo Neira Ayuso This option enables support for connection tracking timeout 172dd705072SPablo Neira Ayuso extension. This allows you to attach timeout policies to flow 173dd705072SPablo Neira Ayuso via the CT target. 174dd705072SPablo Neira Ayuso 175dd705072SPablo Neira Ayuso If unsure, say `N'. 176dd705072SPablo Neira Ayuso 177a992ca2aSPablo Neira Ayusoconfig NF_CONNTRACK_TIMESTAMP 178a992ca2aSPablo Neira Ayuso bool 'Connection tracking timestamping' 179a992ca2aSPablo Neira Ayuso depends on NETFILTER_ADVANCED 180a992ca2aSPablo Neira Ayuso help 181a992ca2aSPablo Neira Ayuso This option enables support for connection tracking timestamping. 182a992ca2aSPablo Neira Ayuso This allows you to store the flow start-time and to obtain 183a992ca2aSPablo Neira Ayuso the flow-stop time (once it has been destroyed) via Connection 184a992ca2aSPablo Neira Ayuso tracking events. 185a992ca2aSPablo Neira Ayuso 186a992ca2aSPablo Neira Ayuso If unsure, say `N'. 187a992ca2aSPablo Neira Ayuso 188c539f017SFlorian Westphalconfig NF_CONNTRACK_LABELS 1897bdfcea8SFlorian Westphal bool "Connection tracking labels" 190c539f017SFlorian Westphal help 191c539f017SFlorian Westphal This option enables support for assigning user-defined flag bits 1927bdfcea8SFlorian Westphal to connection tracking entries. It can be used with xtables connlabel 1937bdfcea8SFlorian Westphal match and the nftables ct expression. 194c539f017SFlorian Westphal 195c0c3ab63SXin Longconfig NF_CONNTRACK_OVS 196c0c3ab63SXin Long bool 197c0c3ab63SXin Long 198f09943feSPatrick McHardyconfig NF_CT_PROTO_GRE 19922fc4c4cSFlorian Westphal bool 200f09943feSPatrick McHardy 2019fb9cbb1SYasuyuki Kozakaiconfig NF_CT_PROTO_SCTP 202a85406afSDavide Caratti bool 'SCTP protocol connection tracking support' 20333b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 204a85406afSDavide Caratti default y 20599de9d40SEric Biggers select NET_CRC32C 2069fb9cbb1SYasuyuki Kozakai help 2079fb9cbb1SYasuyuki Kozakai With this option enabled, the layer 3 independent connection 2089fb9cbb1SYasuyuki Kozakai tracking code will be able to do state tracking on SCTP connections. 2099fb9cbb1SYasuyuki Kozakai 210a85406afSDavide Caratti If unsure, say Y. 2119fb9cbb1SYasuyuki Kozakai 21216958900SPatrick McHardyconfig NF_CONNTRACK_AMANDA 213c9386cfdSPatrick McHardy tristate "Amanda backup protocol support" 21433b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 21516958900SPatrick McHardy select TEXTSEARCH 21616958900SPatrick McHardy select TEXTSEARCH_KMP 21716958900SPatrick McHardy help 21816958900SPatrick McHardy If you are running the Amanda backup package <http://www.amanda.org/> 21916958900SPatrick McHardy on this machine or machines that will be MASQUERADED through this 22016958900SPatrick McHardy machine, then you may want to enable this feature. This allows the 22116958900SPatrick McHardy connection tracking and natting code to allow the sub-channels that 22216958900SPatrick McHardy Amanda requires for communication of the backup data, messages and 22316958900SPatrick McHardy index. 22416958900SPatrick McHardy 22516958900SPatrick McHardy To compile it as a module, choose M here. If unsure, say N. 22616958900SPatrick McHardy 2279fb9cbb1SYasuyuki Kozakaiconfig NF_CONNTRACK_FTP 228c9386cfdSPatrick McHardy tristate "FTP protocol support" 22933b8e776SPatrick McHardy default m if NETFILTER_ADVANCED=n 2309fb9cbb1SYasuyuki Kozakai help 2319fb9cbb1SYasuyuki Kozakai Tracking FTP connections is problematic: special helpers are 2329fb9cbb1SYasuyuki Kozakai required for tracking them, and doing masquerading and other forms 2339fb9cbb1SYasuyuki Kozakai of Network Address Translation on them. 2349fb9cbb1SYasuyuki Kozakai 2359fb9cbb1SYasuyuki Kozakai This is FTP support on Layer 3 independent connection tracking. 2369fb9cbb1SYasuyuki Kozakai 2379fb9cbb1SYasuyuki Kozakai To compile it as a module, choose M here. If unsure, say N. 2389fb9cbb1SYasuyuki Kozakai 239f587de0eSPatrick McHardyconfig NF_CONNTRACK_H323 2408ce22fcaSPatrick McHardy tristate "H.323 protocol support" 24133b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 242f587de0eSPatrick McHardy help 243f587de0eSPatrick McHardy H.323 is a VoIP signalling protocol from ITU-T. As one of the most 244f587de0eSPatrick McHardy important VoIP protocols, it is widely used by voice hardware and 245f587de0eSPatrick McHardy software including voice gateways, IP phones, Netmeeting, OpenPhone, 246f587de0eSPatrick McHardy Gnomemeeting, etc. 247f587de0eSPatrick McHardy 248f587de0eSPatrick McHardy With this module you can support H.323 on a connection tracking/NAT 249f587de0eSPatrick McHardy firewall. 250f587de0eSPatrick McHardy 251f587de0eSPatrick McHardy This module supports RAS, Fast Start, H.245 Tunnelling, Call 252f587de0eSPatrick McHardy Forwarding, RTP/RTCP and T.120 based audio, video, fax, chat, 253f587de0eSPatrick McHardy whiteboard, file transfer, etc. For more information, please 254f587de0eSPatrick McHardy visit http://nath323.sourceforge.net/. 255f587de0eSPatrick McHardy 256f587de0eSPatrick McHardy To compile it as a module, choose M here. If unsure, say N. 257f587de0eSPatrick McHardy 258869f37d8SPatrick McHardyconfig NF_CONNTRACK_IRC 259*57f94001SFlorian Westphal tristate "IRC DCC protocol support (obsolete)" 260869f37d8SPatrick McHardy help 261869f37d8SPatrick McHardy There is a commonly-used extension to IRC called 262869f37d8SPatrick McHardy Direct Client-to-Client Protocol (DCC). This enables users to send 263869f37d8SPatrick McHardy files to each other, and also chat to each other without the need 264869f37d8SPatrick McHardy of a server. DCC Sending is used anywhere you send files over IRC, 265869f37d8SPatrick McHardy and DCC Chat is most commonly used by Eggdrop bots. If you are 266869f37d8SPatrick McHardy using NAT, this extension will enable you to send files and initiate 267869f37d8SPatrick McHardy chats. Note that you do NOT need this extension to get files or 268869f37d8SPatrick McHardy have others initiate chats, or everything else in IRC. 269*57f94001SFlorian Westphal DCC tracking behind NAT requires plaintext (unencrypted) IRC, so 270*57f94001SFlorian Westphal this helper is of limited use these days. 271869f37d8SPatrick McHardy 272869f37d8SPatrick McHardy To compile it as a module, choose M here. If unsure, say N. 273869f37d8SPatrick McHardy 27493557f53SJiri Olsaconfig NF_CONNTRACK_BROADCAST 27593557f53SJiri Olsa tristate 27693557f53SJiri Olsa 27792703eeeSPatrick McHardyconfig NF_CONNTRACK_NETBIOS_NS 2788ce22fcaSPatrick McHardy tristate "NetBIOS name service protocol support" 27993557f53SJiri Olsa select NF_CONNTRACK_BROADCAST 28092703eeeSPatrick McHardy help 28192703eeeSPatrick McHardy NetBIOS name service requests are sent as broadcast messages from an 28292703eeeSPatrick McHardy unprivileged port and responded to with unicast messages to the 28392703eeeSPatrick McHardy same port. This make them hard to firewall properly because connection 28492703eeeSPatrick McHardy tracking doesn't deal with broadcasts. This helper tracks locally 28592703eeeSPatrick McHardy originating NetBIOS name service requests and the corresponding 28692703eeeSPatrick McHardy responses. It relies on correct IP address configuration, specifically 28792703eeeSPatrick McHardy netmask and broadcast address. When properly configured, the output 28892703eeeSPatrick McHardy of "ip address show" should look similar to this: 28992703eeeSPatrick McHardy 29092703eeeSPatrick McHardy $ ip -4 address show eth0 29192703eeeSPatrick McHardy 4: eth0: <BROADCAST,MULTICAST,UP> mtu 1500 qdisc pfifo_fast qlen 1000 29292703eeeSPatrick McHardy inet 172.16.2.252/24 brd 172.16.2.255 scope global eth0 29392703eeeSPatrick McHardy 29492703eeeSPatrick McHardy To compile it as a module, choose M here. If unsure, say N. 29592703eeeSPatrick McHardy 29693557f53SJiri Olsaconfig NF_CONNTRACK_SNMP 29793557f53SJiri Olsa tristate "SNMP service protocol support" 29893557f53SJiri Olsa depends on NETFILTER_ADVANCED 29993557f53SJiri Olsa select NF_CONNTRACK_BROADCAST 30093557f53SJiri Olsa help 30193557f53SJiri Olsa SNMP service requests are sent as broadcast messages from an 30293557f53SJiri Olsa unprivileged port and responded to with unicast messages to the 30393557f53SJiri Olsa same port. This make them hard to firewall properly because connection 30493557f53SJiri Olsa tracking doesn't deal with broadcasts. This helper tracks locally 30593557f53SJiri Olsa originating SNMP service requests and the corresponding 30693557f53SJiri Olsa responses. It relies on correct IP address configuration, specifically 30793557f53SJiri Olsa netmask and broadcast address. 30893557f53SJiri Olsa 30993557f53SJiri Olsa To compile it as a module, choose M here. If unsure, say N. 31093557f53SJiri Olsa 311f09943feSPatrick McHardyconfig NF_CONNTRACK_PPTP 312*57f94001SFlorian Westphal tristate "PPtP protocol support (deprecated)" 31333b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 314f09943feSPatrick McHardy select NF_CT_PROTO_GRE 315f09943feSPatrick McHardy help 316f09943feSPatrick McHardy This module adds support for PPTP (Point to Point Tunnelling 317f09943feSPatrick McHardy Protocol, RFC2637) connection tracking and NAT. 318f09943feSPatrick McHardy 319*57f94001SFlorian Westphal If you are still running PPTP sessions over a stateful firewall or NAT 320f09943feSPatrick McHardy box, you may want to enable this feature. 321f09943feSPatrick McHardy 322*57f94001SFlorian Westphal Please note that not all PPTP modes of operation are supported. 323f09943feSPatrick McHardy Specifically these limitations exist: 3243dde6ad8SDavid Sterba - Blindly assumes that control connections are always established 325f09943feSPatrick McHardy in PNS->PAC direction. This is a violation of RFC2637. 326f09943feSPatrick McHardy - Only supports a single call within each session 327f09943feSPatrick McHardy 328f09943feSPatrick McHardy To compile it as a module, choose M here. If unsure, say N. 329f09943feSPatrick McHardy 3306fecd198SMichal Schmidtconfig NF_CONNTRACK_SANE 331663ef0d1SKees Cook tristate "SANE protocol support" 33233b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 3336fecd198SMichal Schmidt help 3346fecd198SMichal Schmidt SANE is a protocol for remote access to scanners as implemented 3356fecd198SMichal Schmidt by the 'saned' daemon. Like FTP, it uses separate control and 3366fecd198SMichal Schmidt data connections. 3376fecd198SMichal Schmidt 3386fecd198SMichal Schmidt With this module you can support SANE on a connection tracking 3396fecd198SMichal Schmidt firewall. 3406fecd198SMichal Schmidt 3416fecd198SMichal Schmidt To compile it as a module, choose M here. If unsure, say N. 3426fecd198SMichal Schmidt 3439fafcd7bSPatrick McHardyconfig NF_CONNTRACK_SIP 3448ce22fcaSPatrick McHardy tristate "SIP protocol support" 34533b8e776SPatrick McHardy default m if NETFILTER_ADVANCED=n 3469fafcd7bSPatrick McHardy help 3479fafcd7bSPatrick McHardy SIP is an application-layer control protocol that can establish, 3489fafcd7bSPatrick McHardy modify, and terminate multimedia sessions (conferences) such as 34905ba4c89SYonatan Goldschmidt Internet telephony calls. With the nf_conntrack_sip and 3509fafcd7bSPatrick McHardy the nf_nat_sip modules you can support the protocol on a connection 3519fafcd7bSPatrick McHardy tracking/NATing firewall. 3529fafcd7bSPatrick McHardy 3539fafcd7bSPatrick McHardy To compile it as a module, choose M here. If unsure, say N. 3549fafcd7bSPatrick McHardy 355a536df35SPatrick McHardyconfig NF_CONNTRACK_TFTP 356c9386cfdSPatrick McHardy tristate "TFTP protocol support" 35733b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 358a536df35SPatrick McHardy help 359a536df35SPatrick McHardy TFTP connection tracking helper, this is required depending 360a536df35SPatrick McHardy on how restrictive your ruleset is. 361a536df35SPatrick McHardy If you are using a tftp client behind -j SNAT or -j MASQUERADING 362a536df35SPatrick McHardy you will need this. 363a536df35SPatrick McHardy 364a536df35SPatrick McHardy To compile it as a module, choose M here. If unsure, say N. 365a536df35SPatrick McHardy 366c1d10adbSPablo Neira Ayusoconfig NF_CT_NETLINK 3678ce22fcaSPatrick McHardy tristate 'Connection tracking netlink interface' 3682eeeba39SPatrick McHardy select NETFILTER_NETLINK 36933b8e776SPatrick McHardy default m if NETFILTER_ADVANCED=n 370c1d10adbSPablo Neira Ayuso help 371c1d10adbSPablo Neira Ayuso This option enables support for a netlink-based userspace interface 372c1d10adbSPablo Neira Ayuso 37350978462SPablo Neira Ayusoconfig NF_CT_NETLINK_TIMEOUT 37450978462SPablo Neira Ayuso tristate 'Connection tracking timeout tuning via Netlink' 37550978462SPablo Neira Ayuso select NETFILTER_NETLINK 37650978462SPablo Neira Ayuso depends on NETFILTER_ADVANCED 377c7530326SHarsha Sharma depends on NF_CONNTRACK_TIMEOUT 37850978462SPablo Neira Ayuso help 37950978462SPablo Neira Ayuso This option enables support for connection tracking timeout 38050978462SPablo Neira Ayuso fine-grain tuning. This allows you to attach specific timeout 38150978462SPablo Neira Ayuso policies to flows, instead of using the global timeout policy. 38250978462SPablo Neira Ayuso 38350978462SPablo Neira Ayuso If unsure, say `N'. 38450978462SPablo Neira Ayuso 3856e9c2db3SPablo Neira Ayusoconfig NF_CT_NETLINK_HELPER 3866e9c2db3SPablo Neira Ayuso tristate 'Connection tracking helpers in user-space via Netlink' 3876e9c2db3SPablo Neira Ayuso select NETFILTER_NETLINK 3886e9c2db3SPablo Neira Ayuso depends on NF_CT_NETLINK 3896e9c2db3SPablo Neira Ayuso depends on NETFILTER_NETLINK_QUEUE 39083f3e94dSKen-ichirou MATSUZAWA depends on NETFILTER_NETLINK_GLUE_CT 3916e9c2db3SPablo Neira Ayuso depends on NETFILTER_ADVANCED 3926e9c2db3SPablo Neira Ayuso help 3936e9c2db3SPablo Neira Ayuso This option enables the user-space connection tracking helpers 3946e9c2db3SPablo Neira Ayuso infrastructure. 3956e9c2db3SPablo Neira Ayuso 3966e9c2db3SPablo Neira Ayuso If unsure, say `N'. 3976e9c2db3SPablo Neira Ayuso 39883f3e94dSKen-ichirou MATSUZAWAconfig NETFILTER_NETLINK_GLUE_CT 399a29a9a58SKen-ichirou MATSUZAWA bool "NFQUEUE and NFLOG integration with Connection Tracking" 4007c622345SPablo Neira Ayuso default n 401a29a9a58SKen-ichirou MATSUZAWA depends on (NETFILTER_NETLINK_QUEUE || NETFILTER_NETLINK_LOG) && NF_CT_NETLINK 4027c622345SPablo Neira Ayuso help 403a29a9a58SKen-ichirou MATSUZAWA If this option is enabled, NFQUEUE and NFLOG can include 404a29a9a58SKen-ichirou MATSUZAWA Connection Tracking information together with the packet is 405a29a9a58SKen-ichirou MATSUZAWA the enqueued via NFNETLINK. 4067c622345SPablo Neira Ayuso 407c7232c99SPatrick McHardyconfig NF_NAT 4083bf195aeSFlorian Westphal tristate "Network Address Translation support" 4093bf195aeSFlorian Westphal depends on NF_CONNTRACK 4103bf195aeSFlorian Westphal default m if NETFILTER_ADVANCED=n 4113bf195aeSFlorian Westphal help 4123bf195aeSFlorian Westphal The NAT option allows masquerading, port forwarding and other 4133bf195aeSFlorian Westphal forms of full Network Address Port Translation. This can be 4143bf195aeSFlorian Westphal controlled by iptables, ip6tables or nft. 415c7232c99SPatrick McHardy 416ee6eb966SPatrick McHardyconfig NF_NAT_AMANDA 417ee6eb966SPatrick McHardy tristate 418ee6eb966SPatrick McHardy depends on NF_CONNTRACK && NF_NAT 419ee6eb966SPatrick McHardy default NF_NAT && NF_CONNTRACK_AMANDA 420ee6eb966SPatrick McHardy 421d33cbeebSPatrick McHardyconfig NF_NAT_FTP 422d33cbeebSPatrick McHardy tristate 423d33cbeebSPatrick McHardy depends on NF_CONNTRACK && NF_NAT 424d33cbeebSPatrick McHardy default NF_NAT && NF_CONNTRACK_FTP 425d33cbeebSPatrick McHardy 4265901b6beSPablo Neira Ayusoconfig NF_NAT_IRC 4275901b6beSPablo Neira Ayuso tristate 4285901b6beSPablo Neira Ayuso depends on NF_CONNTRACK && NF_NAT 4295901b6beSPablo Neira Ayuso default NF_NAT && NF_CONNTRACK_IRC 4305901b6beSPablo Neira Ayuso 4319a664821SPatrick McHardyconfig NF_NAT_SIP 4329a664821SPatrick McHardy tristate 4339a664821SPatrick McHardy depends on NF_CONNTRACK && NF_NAT 4349a664821SPatrick McHardy default NF_NAT && NF_CONNTRACK_SIP 4359a664821SPatrick McHardy 436320ff567SPablo Neira Ayusoconfig NF_NAT_TFTP 437320ff567SPablo Neira Ayuso tristate 438320ff567SPablo Neira Ayuso depends on NF_CONNTRACK && NF_NAT 439320ff567SPablo Neira Ayuso default NF_NAT && NF_CONNTRACK_TFTP 440320ff567SPablo Neira Ayuso 441b59eaf9eSPablo Neira Ayusoconfig NF_NAT_REDIRECT 4421ac89d20SFlorian Westphal bool 443b59eaf9eSPablo Neira Ayuso 444d1aca8abSFlorian Westphalconfig NF_NAT_MASQUERADE 445d1aca8abSFlorian Westphal bool 446d1aca8abSFlorian Westphal 447ebddb140SXin Longconfig NF_NAT_OVS 448ebddb140SXin Long bool 449ebddb140SXin Long 45048b1de4cSPatrick McHardyconfig NETFILTER_SYNPROXY 45148b1de4cSPatrick McHardy tristate 45248b1de4cSPatrick McHardy 4534b070662SLaszlo Attila Tothendif # NF_CONNTRACK 4544b070662SLaszlo Attila Toth 45596518518SPatrick McHardyconfig NF_TABLES 4565f291c28SEric Leblond select NETFILTER_NETLINK 45799de9d40SEric Biggers select NET_CRC32C 45896518518SPatrick McHardy tristate "Netfilter nf_tables support" 459d497c635SPablo Neira Ayuso help 460d497c635SPablo Neira Ayuso nftables is the new packet classification framework that intends to 461d497c635SPablo Neira Ayuso replace the existing {ip,ip6,arp,eb}_tables infrastructure. It 462d497c635SPablo Neira Ayuso provides a pseudo-state machine with an extensible instruction-set 463d497c635SPablo Neira Ayuso (also known as expressions) that the userspace 'nft' utility 46450935339SAlexander A. Klimov (https://www.netfilter.org/projects/nftables) uses to build the 465d497c635SPablo Neira Ayuso rule-set. It also comes with the generic set infrastructure that 466d497c635SPablo Neira Ayuso allows you to construct mappings between matchings and actions 467d497c635SPablo Neira Ayuso for performance lookups. 468d497c635SPablo Neira Ayuso 469d497c635SPablo Neira Ayuso To compile it as a module, choose M here. 47096518518SPatrick McHardy 471f04e599eSPablo Neira Ayusoif NF_TABLES 4721d49144cSPatrick McHardyconfig NF_TABLES_INET 473f04e599eSPablo Neira Ayuso depends on IPV6 4741d49144cSPatrick McHardy select NF_TABLES_IPV4 4751d49144cSPatrick McHardy select NF_TABLES_IPV6 47602c7b25eSPablo Neira Ayuso bool "Netfilter nf_tables mixed IPv4/IPv6 tables support" 4771d49144cSPatrick McHardy help 4781d49144cSPatrick McHardy This option enables support for a mixed IPv4/IPv6 "inet" table. 4791d49144cSPatrick McHardy 480ed6c4136SPablo Neira Ayusoconfig NF_TABLES_NETDEV 48102c7b25eSPablo Neira Ayuso bool "Netfilter nf_tables netdev tables support" 482ed6c4136SPablo Neira Ayuso help 483ed6c4136SPablo Neira Ayuso This option enables support for the "netdev" table. 484ed6c4136SPablo Neira Ayuso 48591dbc6beSLaura Garcia Liebanaconfig NFT_NUMGEN 48691dbc6beSLaura Garcia Liebana tristate "Netfilter nf_tables number generator module" 48791dbc6beSLaura Garcia Liebana help 48891dbc6beSLaura Garcia Liebana This option adds the number generator expression used to perform 48991dbc6beSLaura Garcia Liebana incremental counting and random numbers bound to a upper limit. 49091dbc6beSLaura Garcia Liebana 49196518518SPatrick McHardyconfig NFT_CT 49296518518SPatrick McHardy depends on NF_CONNTRACK 49396518518SPatrick McHardy tristate "Netfilter nf_tables conntrack module" 494d497c635SPablo Neira Ayuso help 495e4670b05SWilliam Breathitt Gray This option adds the "ct" expression that you can use to match 496d497c635SPablo Neira Ayuso connection tracking information such as the flow state. 49796518518SPatrick McHardy 498fd72f265SPablo Neira Ayusoconfig NFT_EXTHDR_DCCP 499fd72f265SPablo Neira Ayuso bool "Netfilter nf_tables exthdr DCCP support (DEPRECATED)" 500fd72f265SPablo Neira Ayuso default n 501fd72f265SPablo Neira Ayuso help 502fd72f265SPablo Neira Ayuso This option adds support for matching on DCCP extension headers. 503fd72f265SPablo Neira Ayuso 504a3c90f7aSPablo Neira Ayusoconfig NFT_FLOW_OFFLOAD 5059be9d04bSArnd Bergmann depends on NF_CONNTRACK && NF_FLOW_TABLE 506a3c90f7aSPablo Neira Ayuso tristate "Netfilter nf_tables hardware flow offload module" 507a3c90f7aSPablo Neira Ayuso help 508a3c90f7aSPablo Neira Ayuso This option adds the "flow_offload" expression that you can use to 509a3c90f7aSPablo Neira Ayuso choose what flows are placed into the hardware. 510a3c90f7aSPablo Neira Ayuso 511290180e2SPablo Neira Ayusoconfig NFT_CONNLIMIT 512290180e2SPablo Neira Ayuso tristate "Netfilter nf_tables connlimit module" 513290180e2SPablo Neira Ayuso depends on NF_CONNTRACK 514290180e2SPablo Neira Ayuso depends on NETFILTER_ADVANCED 515290180e2SPablo Neira Ayuso select NETFILTER_CONNCOUNT 516290180e2SPablo Neira Ayuso help 517290180e2SPablo Neira Ayuso This option adds the "connlimit" expression that you can use to 518290180e2SPablo Neira Ayuso ratelimit rule matchings per connections. 519290180e2SPablo Neira Ayuso 52096518518SPatrick McHardyconfig NFT_LOG 52196518518SPatrick McHardy tristate "Netfilter nf_tables log module" 522d497c635SPablo Neira Ayuso help 523d497c635SPablo Neira Ayuso This option adds the "log" expression that you can use to log 524d497c635SPablo Neira Ayuso packets matching some criteria. 52596518518SPatrick McHardy 52696518518SPatrick McHardyconfig NFT_LIMIT 52796518518SPatrick McHardy tristate "Netfilter nf_tables limit module" 528d497c635SPablo Neira Ayuso help 529d497c635SPablo Neira Ayuso This option adds the "limit" expression that you can use to 530d497c635SPablo Neira Ayuso ratelimit rule matchings. 53196518518SPatrick McHardy 5329ba1f726SArturo Borreroconfig NFT_MASQ 5339ba1f726SArturo Borrero depends on NF_CONNTRACK 5349ba1f726SArturo Borrero depends on NF_NAT 535a9ce849eSFlorian Westphal select NF_NAT_MASQUERADE 5369ba1f726SArturo Borrero tristate "Netfilter nf_tables masquerade support" 5379ba1f726SArturo Borrero help 5389ba1f726SArturo Borrero This option adds the "masquerade" expression that you can use 5399ba1f726SArturo Borrero to perform NAT in the masquerade flavour. 5409ba1f726SArturo Borrero 541e9105f1bSArturo Borreroconfig NFT_REDIR 542e9105f1bSArturo Borrero depends on NF_CONNTRACK 543e9105f1bSArturo Borrero depends on NF_NAT 544e9105f1bSArturo Borrero tristate "Netfilter nf_tables redirect support" 545c78efc99SFlorian Westphal select NF_NAT_REDIRECT 546e9105f1bSArturo Borrero help 547e9105f1bSArturo Borrero This options adds the "redirect" expression that you can use 548e9105f1bSArturo Borrero to perform NAT in the redirect flavour. 549e9105f1bSArturo Borrero 550eb31628eSTomasz Bursztykaconfig NFT_NAT 551eb31628eSTomasz Bursztyka depends on NF_CONNTRACK 5521e8430f3SPablo Neira Ayuso select NF_NAT 553db8ab388SFlorian Westphal depends on NF_TABLES_IPV4 || NF_TABLES_IPV6 554eb31628eSTomasz Bursztyka tristate "Netfilter nf_tables nat module" 555d497c635SPablo Neira Ayuso help 556d497c635SPablo Neira Ayuso This option adds the "nat" expression that you can use to perform 557d497c635SPablo Neira Ayuso typical Network Address Translation (NAT) packet transformations. 558eb31628eSTomasz Bursztyka 559af308b94SPablo Neira Ayusoconfig NFT_TUNNEL 560af308b94SPablo Neira Ayuso tristate "Netfilter nf_tables tunnel module" 561af308b94SPablo Neira Ayuso help 562af308b94SPablo Neira Ayuso This option adds the "tunnel" expression that you can use to set 563af308b94SPablo Neira Ayuso tunneling policies. 564af308b94SPablo Neira Ayuso 5650aff078dSEric Leblondconfig NFT_QUEUE 5660aff078dSEric Leblond depends on NETFILTER_NETLINK_QUEUE 5670aff078dSEric Leblond tristate "Netfilter nf_tables queue module" 5680aff078dSEric Leblond help 5690aff078dSEric Leblond This is required if you intend to use the userspace queueing 5700aff078dSEric Leblond infrastructure (also known as NFQUEUE) from nftables. 5710aff078dSEric Leblond 5723d2f30a1SPablo Neira Ayusoconfig NFT_QUOTA 5733d2f30a1SPablo Neira Ayuso tristate "Netfilter nf_tables quota module" 5743d2f30a1SPablo Neira Ayuso help 5753d2f30a1SPablo Neira Ayuso This option adds the "quota" expression that you can use to match 5763d2f30a1SPablo Neira Ayuso enforce bytes quotas. 5773d2f30a1SPablo Neira Ayuso 578bee11dc7SEric Leblondconfig NFT_REJECT 579bee11dc7SEric Leblond default m if NETFILTER_ADVANCED=n 580bee11dc7SEric Leblond tristate "Netfilter nf_tables reject support" 581d497c635SPablo Neira Ayuso help 582d497c635SPablo Neira Ayuso This option adds the "reject" expression that you can use to 583d497c635SPablo Neira Ayuso explicitly deny and notify via TCP reset/ICMP informational errors 584d497c635SPablo Neira Ayuso unallowed traffic. 5850ca743a5SPablo Neira Ayuso 58605513e9eSPatrick McHardyconfig NFT_REJECT_INET 58705513e9eSPatrick McHardy depends on NF_TABLES_INET 58805513e9eSPatrick McHardy default NFT_REJECT 58905513e9eSPatrick McHardy tristate 59005513e9eSPatrick McHardy 5910ca743a5SPablo Neira Ayusoconfig NFT_COMPAT 5920ca743a5SPablo Neira Ayuso depends on NETFILTER_XTABLES 5930ca743a5SPablo Neira Ayuso tristate "Netfilter x_tables over nf_tables module" 5940ca743a5SPablo Neira Ayuso help 5950ca743a5SPablo Neira Ayuso This is required if you intend to use any of existing 5960ca743a5SPablo Neira Ayuso x_tables match/target extensions over the nf_tables 5970ca743a5SPablo Neira Ayuso framework. 5980ca743a5SPablo Neira Ayuso 599cb1b69b0SLaura Garcia Liebanaconfig NFT_HASH 600cb1b69b0SLaura Garcia Liebana tristate "Netfilter nf_tables hash module" 601cb1b69b0SLaura Garcia Liebana help 602cb1b69b0SLaura Garcia Liebana This option adds the "hash" expression that you can use to perform 603cb1b69b0SLaura Garcia Liebana a hash operation on registers. 604cb1b69b0SLaura Garcia Liebana 605f6d0cbcfSFlorian Westphalconfig NFT_FIB 606f6d0cbcfSFlorian Westphal tristate 607f6d0cbcfSFlorian Westphal 608f6d0cbcfSFlorian Westphalconfig NFT_FIB_INET 609f6d0cbcfSFlorian Westphal depends on NF_TABLES_INET 610f6d0cbcfSFlorian Westphal depends on NFT_FIB_IPV4 611f6d0cbcfSFlorian Westphal depends on NFT_FIB_IPV6 612f6d0cbcfSFlorian Westphal tristate "Netfilter nf_tables fib inet support" 613f6d0cbcfSFlorian Westphal help 614f6d0cbcfSFlorian Westphal This option allows using the FIB expression from the inet table. 615f6d0cbcfSFlorian Westphal The lookup will be delegated to the IPv4 or IPv6 FIB depending 616f6d0cbcfSFlorian Westphal on the protocol of the packet. 617f6d0cbcfSFlorian Westphal 6186c472602SFlorian Westphalconfig NFT_XFRM 6196c472602SFlorian Westphal tristate "Netfilter nf_tables xfrm/IPSec security association matching" 6206c472602SFlorian Westphal depends on XFRM 6216c472602SFlorian Westphal help 6226c472602SFlorian Westphal This option adds an expression that you can use to extract properties 6236c472602SFlorian Westphal of a packets security association. 6246c472602SFlorian Westphal 625554ced0aSMáté Ecklconfig NFT_SOCKET 626554ced0aSMáté Eckl tristate "Netfilter nf_tables socket match support" 627554ced0aSMáté Eckl select NF_SOCKET_IPV4 6285d400a49SMáté Eckl select NF_SOCKET_IPV6 if NF_TABLES_IPV6 629554ced0aSMáté Eckl help 630554ced0aSMáté Eckl This option allows matching for the presence or absence of a 631554ced0aSMáté Eckl corresponding socket and its attributes. 632554ced0aSMáté Eckl 633b96af92dSFernando Fernandez Manceraconfig NFT_OSF 634b96af92dSFernando Fernandez Mancera tristate "Netfilter nf_tables passive OS fingerprint support" 635b96af92dSFernando Fernandez Mancera depends on NETFILTER_ADVANCED 636b96af92dSFernando Fernandez Mancera select NETFILTER_NETLINK_OSF 637b96af92dSFernando Fernandez Mancera help 638b96af92dSFernando Fernandez Mancera This option allows matching packets from an specific OS. 639b96af92dSFernando Fernandez Mancera 6404ed8eb65SMáté Ecklconfig NFT_TPROXY 6414ed8eb65SMáté Eckl tristate "Netfilter nf_tables tproxy support" 6424ed8eb65SMáté Eckl select NF_DEFRAG_IPV4 6434ed8eb65SMáté Eckl select NF_DEFRAG_IPV6 if NF_TABLES_IPV6 6444ed8eb65SMáté Eckl select NF_TPROXY_IPV4 6454ed8eb65SMáté Eckl select NF_TPROXY_IPV6 if NF_TABLES_IPV6 6464ed8eb65SMáté Eckl help 6474ed8eb65SMáté Eckl This makes transparent proxy support available in nftables. 6484ed8eb65SMáté Eckl 649ad49d86eSFernando Fernandez Manceraconfig NFT_SYNPROXY 650ad49d86eSFernando Fernandez Mancera tristate "Netfilter nf_tables SYNPROXY expression support" 651ad49d86eSFernando Fernandez Mancera depends on NF_CONNTRACK && NETFILTER_ADVANCED 652ad49d86eSFernando Fernandez Mancera select NETFILTER_SYNPROXY 653ad49d86eSFernando Fernandez Mancera select SYN_COOKIES 654ad49d86eSFernando Fernandez Mancera help 655ad49d86eSFernando Fernandez Mancera The SYNPROXY expression allows you to intercept TCP connections and 656ad49d86eSFernando Fernandez Mancera establish them using syncookies before they are passed on to the 657ad49d86eSFernando Fernandez Mancera server. This allows to avoid conntrack and server resource usage 658ad49d86eSFernando Fernandez Mancera during SYN-flood attacks. 659ad49d86eSFernando Fernandez Mancera 660502061f8SPablo Neira Ayusoif NF_TABLES_NETDEV 661502061f8SPablo Neira Ayuso 662502061f8SPablo Neira Ayusoconfig NF_DUP_NETDEV 663502061f8SPablo Neira Ayuso tristate "Netfilter packet duplication support" 664502061f8SPablo Neira Ayuso help 665502061f8SPablo Neira Ayuso This option enables the generic packet duplication infrastructure 666502061f8SPablo Neira Ayuso for Netfilter. 667502061f8SPablo Neira Ayuso 668502061f8SPablo Neira Ayusoconfig NFT_DUP_NETDEV 669502061f8SPablo Neira Ayuso tristate "Netfilter nf_tables netdev packet duplication support" 670502061f8SPablo Neira Ayuso select NF_DUP_NETDEV 671502061f8SPablo Neira Ayuso help 672502061f8SPablo Neira Ayuso This option enables packet duplication for the "netdev" family. 673502061f8SPablo Neira Ayuso 67439e6dea2SPablo Neira Ayusoconfig NFT_FWD_NETDEV 67539e6dea2SPablo Neira Ayuso tristate "Netfilter nf_tables netdev packet forwarding support" 67639e6dea2SPablo Neira Ayuso select NF_DUP_NETDEV 67739e6dea2SPablo Neira Ayuso help 67839e6dea2SPablo Neira Ayuso This option enables packet forwarding for the "netdev" family. 67939e6dea2SPablo Neira Ayuso 6806392c226SPablo M. Bermudo Garayconfig NFT_FIB_NETDEV 6816392c226SPablo M. Bermudo Garay depends on NFT_FIB_IPV4 6826392c226SPablo M. Bermudo Garay depends on NFT_FIB_IPV6 6836392c226SPablo M. Bermudo Garay tristate "Netfilter nf_tables netdev fib lookups support" 6846392c226SPablo M. Bermudo Garay help 6856392c226SPablo M. Bermudo Garay This option allows using the FIB expression from the netdev table. 6866392c226SPablo M. Bermudo Garay The lookup will be delegated to the IPv4 or IPv6 FIB depending 6876392c226SPablo M. Bermudo Garay on the protocol of the packet. 6886392c226SPablo M. Bermudo Garay 6896bbb9ad3SJose M. Guisado Gomezconfig NFT_REJECT_NETDEV 6906bbb9ad3SJose M. Guisado Gomez depends on NFT_REJECT_IPV4 6916bbb9ad3SJose M. Guisado Gomez depends on NFT_REJECT_IPV6 6926bbb9ad3SJose M. Guisado Gomez tristate "Netfilter nf_tables netdev REJECT support" 6936bbb9ad3SJose M. Guisado Gomez help 6946bbb9ad3SJose M. Guisado Gomez This option enables the REJECT support from the netdev table. 6956bbb9ad3SJose M. Guisado Gomez The return packet generation will be delegated to the IPv4 6966bbb9ad3SJose M. Guisado Gomez or IPv6 ICMP or TCP RST implementation depending on the 6976bbb9ad3SJose M. Guisado Gomez protocol of the packet. 6986bbb9ad3SJose M. Guisado Gomez 699502061f8SPablo Neira Ayusoendif # NF_TABLES_NETDEV 700502061f8SPablo Neira Ayuso 701f04e599eSPablo Neira Ayusoendif # NF_TABLES 702f04e599eSPablo Neira Ayuso 7037c23b629SPablo Neira Ayusoconfig NF_FLOW_TABLE_INET 7047c23b629SPablo Neira Ayuso tristate "Netfilter flow table mixed IPv4/IPv6 module" 7051e80380bSFelix Fietkau depends on NF_FLOW_TABLE 7067c23b629SPablo Neira Ayuso help 7077c23b629SPablo Neira Ayuso This option adds the flow table mixed IPv4/IPv6 support. 7087c23b629SPablo Neira Ayuso 7097c23b629SPablo Neira Ayuso To compile it as a module, choose M here. 7107c23b629SPablo Neira Ayuso 711ac2a6666SPablo Neira Ayusoconfig NF_FLOW_TABLE 712ac2a6666SPablo Neira Ayuso tristate "Netfilter flow table module" 7136be3bcd7SPablo Neira Ayuso depends on NETFILTER_INGRESS 7146be3bcd7SPablo Neira Ayuso depends on NF_CONNTRACK 7156be3bcd7SPablo Neira Ayuso depends on NF_TABLES 716ac2a6666SPablo Neira Ayuso help 717ac2a6666SPablo Neira Ayuso This option adds the flow table core infrastructure. 718ac2a6666SPablo Neira Ayuso 719ac2a6666SPablo Neira Ayuso To compile it as a module, choose M here. 720ac2a6666SPablo Neira Ayuso 721b0381776SVlad Buslovconfig NF_FLOW_TABLE_PROCFS 722b0381776SVlad Buslov bool "Supply flow table statistics in procfs" 723b06ada6dSPablo Neira Ayuso depends on NF_FLOW_TABLE 724b0381776SVlad Buslov depends on PROC_FS 725b0381776SVlad Buslov help 726b0381776SVlad Buslov This option enables for the flow table offload statistics 727b0381776SVlad Buslov to be shown in procfs under net/netfilter/nf_flowtable. 728b0381776SVlad Buslov 7292e4e6a17SHarald Welteconfig NETFILTER_XTABLES 7302e4e6a17SHarald Welte tristate "Netfilter Xtables support (required for ip_tables)" 73133b8e776SPatrick McHardy default m if NETFILTER_ADVANCED=n 7322e4e6a17SHarald Welte help 7332e4e6a17SHarald Welte This is required if you intend to use any of ip_tables, 7342e4e6a17SHarald Welte ip6_tables or arp_tables. 7352e4e6a17SHarald Welte 736c2df73deSJan Engelhardtif NETFILTER_XTABLES 737c2df73deSJan Engelhardt 73847a6959fSFlorian Westphalconfig NETFILTER_XTABLES_COMPAT 73947a6959fSFlorian Westphal bool "Netfilter Xtables 32bit support" 74047a6959fSFlorian Westphal depends on COMPAT 74147a6959fSFlorian Westphal help 74247a6959fSFlorian Westphal This option provides a translation layer to run 32bit arp,ip(6),ebtables 74347a6959fSFlorian Westphal binaries on 64bit kernels. 74447a6959fSFlorian Westphal 74547a6959fSFlorian Westphal If unsure, say N. 74647a6959fSFlorian Westphal 7479fce6658SPablo Neira Ayusoconfig NETFILTER_XTABLES_LEGACY 7489fce6658SPablo Neira Ayuso bool "Netfilter legacy tables support" 7499fce6658SPablo Neira Ayuso depends on !PREEMPT_RT 7509fce6658SPablo Neira Ayuso help 7519fce6658SPablo Neira Ayuso Say Y here if you still require support for legacy tables. This is 7529fce6658SPablo Neira Ayuso required by the legacy tools (iptables-legacy) and is not needed if 7539fce6658SPablo Neira Ayuso you use iptables over nftables (iptables-nft). 7549fce6658SPablo Neira Ayuso Legacy support is not limited to IP, it also includes EBTABLES and 7559fce6658SPablo Neira Ayuso ARPTABLES. 7569fce6658SPablo Neira Ayuso 75728b94988SJan Engelhardtcomment "Xtables combined modules" 75828b94988SJan Engelhardt 75928b94988SJan Engelhardtconfig NETFILTER_XT_MARK 76028b94988SJan Engelhardt tristate 'nfmark target and match support' 76128b94988SJan Engelhardt default m if NETFILTER_ADVANCED=n 762a7f7f624SMasahiro Yamada help 76328b94988SJan Engelhardt This option adds the "MARK" target and "mark" match. 76428b94988SJan Engelhardt 76528b94988SJan Engelhardt Netfilter mark matching allows you to match packets based on the 76628b94988SJan Engelhardt "nfmark" value in the packet. 76728b94988SJan Engelhardt The target allows you to create rules in the "mangle" table which alter 76828b94988SJan Engelhardt the netfilter mark (nfmark) field associated with the packet. 76928b94988SJan Engelhardt 770f1504307SMoritz Sichert Prior to routing, the nfmark can influence the routing method and can 771f1504307SMoritz Sichert also be used by other subsystems to change their behavior. 77228b94988SJan Engelhardt 773b8f00ba2SJan Engelhardtconfig NETFILTER_XT_CONNMARK 774b8f00ba2SJan Engelhardt tristate 'ctmark target and match support' 775b8f00ba2SJan Engelhardt depends on NF_CONNTRACK 776b8f00ba2SJan Engelhardt depends on NETFILTER_ADVANCED 777b8f00ba2SJan Engelhardt select NF_CONNTRACK_MARK 778a7f7f624SMasahiro Yamada help 779b8f00ba2SJan Engelhardt This option adds the "CONNMARK" target and "connmark" match. 780b8f00ba2SJan Engelhardt 781b8f00ba2SJan Engelhardt Netfilter allows you to store a mark value per connection (a.k.a. 782b8f00ba2SJan Engelhardt ctmark), similarly to the packet mark (nfmark). Using this 783b8f00ba2SJan Engelhardt target and match, you can set and match on this mark. 784b8f00ba2SJan Engelhardt 785d956798dSJozsef Kadlecsikconfig NETFILTER_XT_SET 786d956798dSJozsef Kadlecsik tristate 'set target and match support' 787d956798dSJozsef Kadlecsik depends on IP_SET 788d956798dSJozsef Kadlecsik depends on NETFILTER_ADVANCED 789d956798dSJozsef Kadlecsik help 790d956798dSJozsef Kadlecsik This option adds the "SET" target and "set" match. 791d956798dSJozsef Kadlecsik 792d956798dSJozsef Kadlecsik Using this target and match, you can add/delete and match 793d956798dSJozsef Kadlecsik elements in the sets created by ipset(8). 794d956798dSJozsef Kadlecsik 795d956798dSJozsef Kadlecsik To compile it as a module, choose M here. If unsure, say N. 796d956798dSJozsef Kadlecsik 7972e4e6a17SHarald Welte# alphabetically ordered list of targets 7982e4e6a17SHarald Welte 79944c58731SJan Engelhardtcomment "Xtables targets" 80044c58731SJan Engelhardt 80143f393caSThomas Grafconfig NETFILTER_XT_TARGET_AUDIT 80243f393caSThomas Graf tristate "AUDIT target support" 80343f393caSThomas Graf depends on AUDIT 80443f393caSThomas Graf depends on NETFILTER_ADVANCED 805a7f7f624SMasahiro Yamada help 80643f393caSThomas Graf This option adds a 'AUDIT' target, which can be used to create 80743f393caSThomas Graf audit records for packets dropped/accepted. 80843f393caSThomas Graf 80943f393caSThomas Graf To compileit as a module, choose M here. If unsure, say N. 81043f393caSThomas Graf 811edf0e1fbSMichael S. Tsirkinconfig NETFILTER_XT_TARGET_CHECKSUM 812edf0e1fbSMichael S. Tsirkin tristate "CHECKSUM target support" 813a9525c7fSFlorian Westphal depends on IP_NF_MANGLE || IP6_NF_MANGLE || NFT_COMPAT 814edf0e1fbSMichael S. Tsirkin depends on NETFILTER_ADVANCED 815a7f7f624SMasahiro Yamada help 816edf0e1fbSMichael S. Tsirkin This option adds a `CHECKSUM' target, which can be used in the iptables mangle 81710568f6cSFlorian Westphal table to work around buggy DHCP clients in virtualized environments. 818edf0e1fbSMichael S. Tsirkin 81910568f6cSFlorian Westphal Some old DHCP clients drop packets because they are not aware 82010568f6cSFlorian Westphal that the checksum would normally be offloaded to hardware and 82110568f6cSFlorian Westphal thus should be considered valid. 82210568f6cSFlorian Westphal This target can be used to fill in the checksum using iptables 82310568f6cSFlorian Westphal when such packets are sent via a virtual network device. 824edf0e1fbSMichael S. Tsirkin 825edf0e1fbSMichael S. Tsirkin To compile it as a module, choose M here. If unsure, say N. 826edf0e1fbSMichael S. Tsirkin 8272e4e6a17SHarald Welteconfig NETFILTER_XT_TARGET_CLASSIFY 8282e4e6a17SHarald Welte tristate '"CLASSIFY" target support' 82933b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 8302e4e6a17SHarald Welte help 8312e4e6a17SHarald Welte This option adds a `CLASSIFY' target, which enables the user to set 8322e4e6a17SHarald Welte the priority of a packet. Some qdiscs can use this value for 8332e4e6a17SHarald Welte classification, among these are: 8342e4e6a17SHarald Welte 8352e4e6a17SHarald Welte atm, cbq, dsmark, pfifo_fast, htb, prio 8362e4e6a17SHarald Welte 8372e4e6a17SHarald Welte To compile it as a module, choose M here. If unsure, say N. 8382e4e6a17SHarald Welte 8392e4e6a17SHarald Welteconfig NETFILTER_XT_TARGET_CONNMARK 8402e4e6a17SHarald Welte tristate '"CONNMARK" target support' 841587aa641SPatrick McHardy depends on NF_CONNTRACK 84233b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 843b8f00ba2SJan Engelhardt select NETFILTER_XT_CONNMARK 844a7f7f624SMasahiro Yamada help 845b8f00ba2SJan Engelhardt This is a backwards-compat option for the user's convenience 846b8f00ba2SJan Engelhardt (e.g. when running oldconfig). It selects 847b8f00ba2SJan Engelhardt CONFIG_NETFILTER_XT_CONNMARK (combined connmark/CONNMARK module). 8482e4e6a17SHarald Welte 849aba0d348SJan Engelhardtconfig NETFILTER_XT_TARGET_CONNSECMARK 850aba0d348SJan Engelhardt tristate '"CONNSECMARK" target support' 851c2df73deSJan Engelhardt depends on NF_CONNTRACK && NF_CONNTRACK_SECMARK 852aba0d348SJan Engelhardt default m if NETFILTER_ADVANCED=n 853aba0d348SJan Engelhardt help 854aba0d348SJan Engelhardt The CONNSECMARK target copies security markings from packets 855aba0d348SJan Engelhardt to connections, and restores security markings from connections 856aba0d348SJan Engelhardt to packets (if the packets are not already marked). This would 857aba0d348SJan Engelhardt normally be used in conjunction with the SECMARK target. 858aba0d348SJan Engelhardt 859aba0d348SJan Engelhardt To compile it as a module, choose M here. If unsure, say N. 860aba0d348SJan Engelhardt 86184f3bb9aSPatrick McHardyconfig NETFILTER_XT_TARGET_CT 86284f3bb9aSPatrick McHardy tristate '"CT" target support' 86384f3bb9aSPatrick McHardy depends on NF_CONNTRACK 864a9525c7fSFlorian Westphal depends on IP_NF_RAW || IP6_NF_RAW || NFT_COMPAT 86584f3bb9aSPatrick McHardy depends on NETFILTER_ADVANCED 86684f3bb9aSPatrick McHardy help 86784f3bb9aSPatrick McHardy This options adds a `CT' target, which allows to specify initial 86884f3bb9aSPatrick McHardy connection tracking parameters like events to be delivered and 86984f3bb9aSPatrick McHardy the helper to be used. 87084f3bb9aSPatrick McHardy 87184f3bb9aSPatrick McHardy To compile it as a module, choose M here. If unsure, say N. 87284f3bb9aSPatrick McHardy 873a468701dSYasuyuki Kozakaiconfig NETFILTER_XT_TARGET_DSCP 874c9fd4968SJan Engelhardt tristate '"DSCP" and "TOS" target support' 875a9525c7fSFlorian Westphal depends on IP_NF_MANGLE || IP6_NF_MANGLE || NFT_COMPAT 87633b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 877a468701dSYasuyuki Kozakai help 878a468701dSYasuyuki Kozakai This option adds a `DSCP' target, which allows you to manipulate 879a468701dSYasuyuki Kozakai the IPv4/IPv6 header DSCP field (differentiated services codepoint). 880a468701dSYasuyuki Kozakai 881a468701dSYasuyuki Kozakai The DSCP field can have any value between 0x0 and 0x3f inclusive. 882a468701dSYasuyuki Kozakai 883c9fd4968SJan Engelhardt It also adds the "TOS" target, which allows you to create rules in 884c9fd4968SJan Engelhardt the "mangle" table which alter the Type Of Service field of an IPv4 8855c350e5aSJan Engelhardt or the Priority field of an IPv6 packet, prior to routing. 886c9fd4968SJan Engelhardt 887a468701dSYasuyuki Kozakai To compile it as a module, choose M here. If unsure, say N. 888a468701dSYasuyuki Kozakai 889563d36ebSJan Engelhardtconfig NETFILTER_XT_TARGET_HL 890563d36ebSJan Engelhardt tristate '"HL" hoplimit target support' 891a9525c7fSFlorian Westphal depends on IP_NF_MANGLE || IP6_NF_MANGLE || NFT_COMPAT 892563d36ebSJan Engelhardt depends on NETFILTER_ADVANCED 893a7f7f624SMasahiro Yamada help 894563d36ebSJan Engelhardt This option adds the "HL" (for IPv6) and "TTL" (for IPv4) 895563d36ebSJan Engelhardt targets, which enable the user to change the 896563d36ebSJan Engelhardt hoplimit/time-to-live value of the IP header. 897563d36ebSJan Engelhardt 898563d36ebSJan Engelhardt While it is safe to decrement the hoplimit/TTL value, the 899563d36ebSJan Engelhardt modules also allow to increment and set the hoplimit value of 900563d36ebSJan Engelhardt the header to arbitrary values. This is EXTREMELY DANGEROUS 901563d36ebSJan Engelhardt since you can easily create immortal packets that loop 902563d36ebSJan Engelhardt forever on the network. 903563d36ebSJan Engelhardt 904cf308a1fSHans Schillstromconfig NETFILTER_XT_TARGET_HMARK 905cf308a1fSHans Schillstrom tristate '"HMARK" target support' 906f09becc7SPablo Neira Ayuso depends on IP6_NF_IPTABLES || IP6_NF_IPTABLES=n 907cf308a1fSHans Schillstrom depends on NETFILTER_ADVANCED 908a7f7f624SMasahiro Yamada help 909cf308a1fSHans Schillstrom This option adds the "HMARK" target. 910cf308a1fSHans Schillstrom 911cf308a1fSHans Schillstrom The target allows you to create rules in the "raw" and "mangle" tables 912cf308a1fSHans Schillstrom which set the skbuff mark by means of hash calculation within a given 913f1504307SMoritz Sichert range. The nfmark can influence the routing method and can also be used 914f1504307SMoritz Sichert by other subsystems to change their behaviour. 915cf308a1fSHans Schillstrom 916cf308a1fSHans Schillstrom To compile it as a module, choose M here. If unsure, say N. 917cf308a1fSHans Schillstrom 9180902b469SLuciano Coelhoconfig NETFILTER_XT_TARGET_IDLETIMER 9190902b469SLuciano Coelho tristate "IDLETIMER target support" 9200902b469SLuciano Coelho depends on NETFILTER_ADVANCED 9210902b469SLuciano Coelho help 9220902b469SLuciano Coelho 9230902b469SLuciano Coelho This option adds the `IDLETIMER' target. Each matching packet 9240902b469SLuciano Coelho resets the timer associated with label specified when the rule is 9250902b469SLuciano Coelho added. When the timer expires, it triggers a sysfs notification. 9260902b469SLuciano Coelho The remaining time for expiration can be read via sysfs. 9270902b469SLuciano Coelho 9280902b469SLuciano Coelho To compile it as a module, choose M here. If unsure, say N. 9290902b469SLuciano Coelho 930268cb38eSAdam Nielsenconfig NETFILTER_XT_TARGET_LED 931268cb38eSAdam Nielsen tristate '"LED" target support' 9323ae16f13SAlex Riesen depends on LEDS_CLASS && LEDS_TRIGGERS 933268cb38eSAdam Nielsen depends on NETFILTER_ADVANCED 934268cb38eSAdam Nielsen help 935268cb38eSAdam Nielsen This option adds a `LED' target, which allows you to blink LEDs in 936268cb38eSAdam Nielsen response to particular packets passing through your machine. 937268cb38eSAdam Nielsen 938268cb38eSAdam Nielsen This can be used to turn a spare LED into a network activity LED, 939268cb38eSAdam Nielsen which only flashes in response to FTP transfers, for example. Or 940268cb38eSAdam Nielsen you could have an LED which lights up for a minute or two every time 941268cb38eSAdam Nielsen somebody connects to your machine via SSH. 942268cb38eSAdam Nielsen 943268cb38eSAdam Nielsen You will need support for the "led" class to make this work. 944268cb38eSAdam Nielsen 945268cb38eSAdam Nielsen To create an LED trigger for incoming SSH traffic: 946268cb38eSAdam Nielsen iptables -A INPUT -p tcp --dport 22 -j LED --led-trigger-id ssh --led-delay 1000 947268cb38eSAdam Nielsen 948268cb38eSAdam Nielsen Then attach the new trigger to an LED on your system: 949268cb38eSAdam Nielsen echo netfilter-ssh > /sys/class/leds/<ledname>/trigger 950268cb38eSAdam Nielsen 951268cb38eSAdam Nielsen For more information on the LEDs available on your system, see 9528dab9197SMauro Carvalho Chehab Documentation/leds/leds-class.rst 953268cb38eSAdam Nielsen 9546939c33aSRichard Weinbergerconfig NETFILTER_XT_TARGET_LOG 9556939c33aSRichard Weinberger tristate "LOG target support" 956db3187aeSFlorian Westphal select NF_LOG_SYSLOG 9575d400a49SMáté Eckl select NF_LOG_IPV6 if IP6_NF_IPTABLES 9586939c33aSRichard Weinberger default m if NETFILTER_ADVANCED=n 9596939c33aSRichard Weinberger help 9606939c33aSRichard Weinberger This option adds a `LOG' target, which allows you to create rules in 9616939c33aSRichard Weinberger any iptables table which records the packet header to the syslog. 9626939c33aSRichard Weinberger 9636939c33aSRichard Weinberger To compile it as a module, choose M here. If unsure, say N. 9646939c33aSRichard Weinberger 9652e4e6a17SHarald Welteconfig NETFILTER_XT_TARGET_MARK 9662e4e6a17SHarald Welte tristate '"MARK" target support' 96728b94988SJan Engelhardt depends on NETFILTER_ADVANCED 96828b94988SJan Engelhardt select NETFILTER_XT_MARK 969a7f7f624SMasahiro Yamada help 97028b94988SJan Engelhardt This is a backwards-compat option for the user's convenience 97128b94988SJan Engelhardt (e.g. when running oldconfig). It selects 97228b94988SJan Engelhardt CONFIG_NETFILTER_XT_MARK (combined mark/MARK module). 9732e4e6a17SHarald Welte 97484a59ca5SPablo Neira Ayusoconfig NETFILTER_XT_NAT 97584a59ca5SPablo Neira Ayuso tristate '"SNAT and DNAT" targets support' 97684a59ca5SPablo Neira Ayuso depends on NF_NAT 977a7f7f624SMasahiro Yamada help 97884a59ca5SPablo Neira Ayuso This option enables the SNAT and DNAT targets. 97984a59ca5SPablo Neira Ayuso 98084a59ca5SPablo Neira Ayuso To compile it as a module, choose M here. If unsure, say N. 98184a59ca5SPablo Neira Ayuso 982b3d54b3eSJan Engelhardtconfig NETFILTER_XT_TARGET_NETMAP 983b3d54b3eSJan Engelhardt tristate '"NETMAP" target support' 984b3d54b3eSJan Engelhardt depends on NF_NAT 985a7f7f624SMasahiro Yamada help 986b3d54b3eSJan Engelhardt NETMAP is an implementation of static 1:1 NAT mapping of network 987b3d54b3eSJan Engelhardt addresses. It maps the network address part, while keeping the host 988b3d54b3eSJan Engelhardt address part intact. 989b3d54b3eSJan Engelhardt 990b3d54b3eSJan Engelhardt To compile it as a module, choose M here. If unsure, say N. 991b3d54b3eSJan Engelhardt 992baf7b1e1SPatrick McHardyconfig NETFILTER_XT_TARGET_NFLOG 993baf7b1e1SPatrick McHardy tristate '"NFLOG" target support' 99433b8e776SPatrick McHardy default m if NETFILTER_ADVANCED=n 995293a4f28SEric Leblond select NETFILTER_NETLINK_LOG 996baf7b1e1SPatrick McHardy help 997baf7b1e1SPatrick McHardy This option enables the NFLOG target, which allows to LOG 998293a4f28SEric Leblond messages through nfnetlink_log. 999baf7b1e1SPatrick McHardy 1000baf7b1e1SPatrick McHardy To compile it as a module, choose M here. If unsure, say N. 1001baf7b1e1SPatrick McHardy 1002aba0d348SJan Engelhardtconfig NETFILTER_XT_TARGET_NFQUEUE 1003aba0d348SJan Engelhardt tristate '"NFQUEUE" target Support' 1004aba0d348SJan Engelhardt depends on NETFILTER_ADVANCED 10055f2cafe7SFlorian Westphal select NETFILTER_NETLINK_QUEUE 1006aba0d348SJan Engelhardt help 1007aba0d348SJan Engelhardt This target replaced the old obsolete QUEUE target. 1008aba0d348SJan Engelhardt 1009aba0d348SJan Engelhardt As opposed to QUEUE, it supports 65535 different queues, 1010aba0d348SJan Engelhardt not just one. 1011aba0d348SJan Engelhardt 1012aba0d348SJan Engelhardt To compile it as a module, choose M here. If unsure, say N. 1013aba0d348SJan Engelhardt 101410db9069SPablo Neira Ayusoconfig NETFILTER_XT_TARGET_NOTRACK 101510db9069SPablo Neira Ayuso tristate '"NOTRACK" target support (DEPRECATED)' 1016757ae316SPablo Neira Ayuso depends on NF_CONNTRACK 1017757ae316SPablo Neira Ayuso depends on IP_NF_RAW || IP6_NF_RAW 1018757ae316SPablo Neira Ayuso depends on NETFILTER_ADVANCED 101910db9069SPablo Neira Ayuso select NETFILTER_XT_TARGET_CT 102010db9069SPablo Neira Ayuso 10215859034dSPatrick McHardyconfig NETFILTER_XT_TARGET_RATEEST 10225859034dSPatrick McHardy tristate '"RATEEST" target support' 1023b26e76b7SPatrick McHardy depends on NETFILTER_ADVANCED 10245859034dSPatrick McHardy help 10255859034dSPatrick McHardy This option adds a `RATEEST' target, which allows to measure 10265859034dSPatrick McHardy rates similar to TC estimators. The `rateest' match can be 10275859034dSPatrick McHardy used to match on the measured rates. 10285859034dSPatrick McHardy 10295859034dSPatrick McHardy To compile it as a module, choose M here. If unsure, say N. 10305859034dSPatrick McHardy 10312cbc78a2SJan Engelhardtconfig NETFILTER_XT_TARGET_REDIRECT 10322cbc78a2SJan Engelhardt tristate "REDIRECT target support" 10332cbc78a2SJan Engelhardt depends on NF_NAT 1034b59eaf9eSPablo Neira Ayuso select NF_NAT_REDIRECT 1035a7f7f624SMasahiro Yamada help 10362cbc78a2SJan Engelhardt REDIRECT is a special case of NAT: all incoming connections are 10372cbc78a2SJan Engelhardt mapped onto the incoming interface's address, causing the packets to 10382cbc78a2SJan Engelhardt come to the local machine instead of passing through. This is 10392cbc78a2SJan Engelhardt useful for transparent proxies. 10402cbc78a2SJan Engelhardt 10412cbc78a2SJan Engelhardt To compile it as a module, choose M here. If unsure, say N. 10422cbc78a2SJan Engelhardt 1043adf82accSFlorian Westphalconfig NETFILTER_XT_TARGET_MASQUERADE 1044adf82accSFlorian Westphal tristate "MASQUERADE target support" 1045adf82accSFlorian Westphal depends on NF_NAT 1046adf82accSFlorian Westphal default m if NETFILTER_ADVANCED=n 1047adf82accSFlorian Westphal select NF_NAT_MASQUERADE 1048adf82accSFlorian Westphal help 1049adf82accSFlorian Westphal Masquerading is a special case of NAT: all outgoing connections are 1050adf82accSFlorian Westphal changed to seem to come from a particular interface's address, and 1051adf82accSFlorian Westphal if the interface goes down, those connections are lost. This is 1052adf82accSFlorian Westphal only useful for dialup accounts with dynamic IP address (ie. your IP 1053adf82accSFlorian Westphal address will be different on next dialup). 1054adf82accSFlorian Westphal 1055adf82accSFlorian Westphal To compile it as a module, choose M here. If unsure, say N. 1056adf82accSFlorian Westphal 1057e281b198SJan Engelhardtconfig NETFILTER_XT_TARGET_TEE 1058fe6fb552SArnd Hannemann tristate '"TEE" - packet cloning to alternate destination' 1059e281b198SJan Engelhardt depends on NETFILTER_ADVANCED 106083827f6aSRandy Dunlap depends on !NF_CONNTRACK || NF_CONNTRACK 1061d1fa3810SArnd Bergmann depends on IP6_NF_IPTABLES || !IP6_NF_IPTABLES 1062bbde9fc1SPablo Neira Ayuso select NF_DUP_IPV4 10635d400a49SMáté Eckl select NF_DUP_IPV6 if IP6_NF_IPTABLES 1064a7f7f624SMasahiro Yamada help 1065e281b198SJan Engelhardt This option adds a "TEE" target with which a packet can be cloned and 1066e281b198SJan Engelhardt this clone be rerouted to another nexthop. 1067e281b198SJan Engelhardt 1068e8439270SKOVACS Krisztianconfig NETFILTER_XT_TARGET_TPROXY 1069fd158d79SFlorian Westphal tristate '"TPROXY" target transparent proxying support' 1070e8439270SKOVACS Krisztian depends on NETFILTER_XTABLES 1071e8439270SKOVACS Krisztian depends on NETFILTER_ADVANCED 1072f09becc7SPablo Neira Ayuso depends on IP6_NF_IPTABLES || IP6_NF_IPTABLES=n 1073a9525c7fSFlorian Westphal depends on IP_NF_MANGLE || NFT_COMPAT 1074e8439270SKOVACS Krisztian select NF_DEFRAG_IPV4 107574ec4d55SArnd Bergmann select NF_DEFRAG_IPV6 if IP6_NF_IPTABLES != n 107645ca4e0cSMáté Eckl select NF_TPROXY_IPV4 107745ca4e0cSMáté Eckl select NF_TPROXY_IPV6 if IP6_NF_IPTABLES 1078e8439270SKOVACS Krisztian help 1079e8439270SKOVACS Krisztian This option adds a `TPROXY' target, which is somewhat similar to 1080e8439270SKOVACS Krisztian REDIRECT. It can only be used in the mangle table and is useful 1081e8439270SKOVACS Krisztian to redirect traffic to a transparent proxy. It does _not_ depend 1082e8439270SKOVACS Krisztian on Netfilter connection tracking and NAT, unlike REDIRECT. 1083fd158d79SFlorian Westphal For it to work you will have to configure certain iptables rules 1084fd158d79SFlorian Westphal and use policy routing. For more information on how to set it up 10854ac0b122SMauro Carvalho Chehab see Documentation/networking/tproxy.rst. 1086e8439270SKOVACS Krisztian 1087e8439270SKOVACS Krisztian To compile it as a module, choose M here. If unsure, say N. 1088e8439270SKOVACS Krisztian 1089ba9dda3aSJozsef Kadlecsikconfig NETFILTER_XT_TARGET_TRACE 1090ba9dda3aSJozsef Kadlecsik tristate '"TRACE" target support' 1091ba9dda3aSJozsef Kadlecsik depends on IP_NF_RAW || IP6_NF_RAW 109233b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 1093ba9dda3aSJozsef Kadlecsik help 1094ba9dda3aSJozsef Kadlecsik The TRACE target allows you to mark packets so that the kernel 1095ba9dda3aSJozsef Kadlecsik will log every rule which match the packets as those traverse 1096ba9dda3aSJozsef Kadlecsik the tables, chains, rules. 1097ba9dda3aSJozsef Kadlecsik 1098ba9dda3aSJozsef Kadlecsik If you want to compile it as a module, say M here and read 1099cd238effSMauro Carvalho Chehab <file:Documentation/kbuild/modules.rst>. If unsure, say `N'. 1100ba9dda3aSJozsef Kadlecsik 11015e6874cdSJames Morrisconfig NETFILTER_XT_TARGET_SECMARK 11025e6874cdSJames Morris tristate '"SECMARK" target support' 1103c2df73deSJan Engelhardt depends on NETWORK_SECMARK 110433b8e776SPatrick McHardy default m if NETFILTER_ADVANCED=n 11055e6874cdSJames Morris help 11065e6874cdSJames Morris The SECMARK target allows security marking of network 11075e6874cdSJames Morris packets, for use with security subsystems. 11085e6874cdSJames Morris 11095e6874cdSJames Morris To compile it as a module, choose M here. If unsure, say N. 11105e6874cdSJames Morris 1111cdd289a2SPatrick McHardyconfig NETFILTER_XT_TARGET_TCPMSS 1112cdd289a2SPatrick McHardy tristate '"TCPMSS" target support' 111333b8e776SPatrick McHardy default m if NETFILTER_ADVANCED=n 1114a7f7f624SMasahiro Yamada help 1115cdd289a2SPatrick McHardy This option adds a `TCPMSS' target, which allows you to alter the 1116cdd289a2SPatrick McHardy MSS value of TCP SYN packets, to control the maximum size for that 1117cdd289a2SPatrick McHardy connection (usually limiting it to your outgoing interface's MTU 1118cdd289a2SPatrick McHardy minus 40). 1119cdd289a2SPatrick McHardy 1120cdd289a2SPatrick McHardy This is used to overcome criminally braindead ISPs or servers which 1121cdd289a2SPatrick McHardy block ICMP Fragmentation Needed packets. The symptoms of this 1122cdd289a2SPatrick McHardy problem are that everything works fine from your Linux 1123cdd289a2SPatrick McHardy firewall/router, but machines behind it can never exchange large 1124cdd289a2SPatrick McHardy packets: 1125cdd289a2SPatrick McHardy 1) Web browsers connect, then hang with no data received. 1126cdd289a2SPatrick McHardy 2) Small mail works fine, but large emails hang. 1127cdd289a2SPatrick McHardy 3) ssh works fine, but scp hangs after initial handshaking. 1128cdd289a2SPatrick McHardy 1129cdd289a2SPatrick McHardy Workaround: activate this option and add a rule to your firewall 1130cdd289a2SPatrick McHardy configuration like: 1131cdd289a2SPatrick McHardy 1132cdd289a2SPatrick McHardy iptables -A FORWARD -p tcp --tcp-flags SYN,RST SYN \ 1133cdd289a2SPatrick McHardy -j TCPMSS --clamp-mss-to-pmtu 1134cdd289a2SPatrick McHardy 1135cdd289a2SPatrick McHardy To compile it as a module, choose M here. If unsure, say N. 1136cdd289a2SPatrick McHardy 1137338e8a79SSven Schnelleconfig NETFILTER_XT_TARGET_TCPOPTSTRIP 1138663ef0d1SKees Cook tristate '"TCPOPTSTRIP" target support' 1139a9525c7fSFlorian Westphal depends on IP_NF_MANGLE || IP6_NF_MANGLE || NFT_COMPAT 114033b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 1141338e8a79SSven Schnelle help 1142338e8a79SSven Schnelle This option adds a "TCPOPTSTRIP" target, which allows you to strip 1143338e8a79SSven Schnelle TCP options from TCP packets. 1144338e8a79SSven Schnelle 114544c58731SJan Engelhardt# alphabetically ordered list of matches 114644c58731SJan Engelhardt 114744c58731SJan Engelhardtcomment "Xtables matches" 114844c58731SJan Engelhardt 1149de81bbeaSFlorian Westphalconfig NETFILTER_XT_MATCH_ADDRTYPE 1150de81bbeaSFlorian Westphal tristate '"addrtype" address type match support' 11515cca4aceSAnton Blanchard default m if NETFILTER_ADVANCED=n 1152a7f7f624SMasahiro Yamada help 1153de81bbeaSFlorian Westphal This option allows you to match what routing thinks of an address, 1154de81bbeaSFlorian Westphal eg. UNICAST, LOCAL, BROADCAST, ... 1155de81bbeaSFlorian Westphal 1156de81bbeaSFlorian Westphal If you want to compile it as a module, say M here and read 1157cd238effSMauro Carvalho Chehab <file:Documentation/kbuild/modules.rst>. If unsure, say `N'. 1158de81bbeaSFlorian Westphal 1159e6f30c73SWillem de Bruijnconfig NETFILTER_XT_MATCH_BPF 1160e6f30c73SWillem de Bruijn tristate '"bpf" match support' 1161e6f30c73SWillem de Bruijn depends on NETFILTER_ADVANCED 1162e6f30c73SWillem de Bruijn help 1163e6f30c73SWillem de Bruijn BPF matching applies a linux socket filter to each packet and 1164e6f30c73SWillem de Bruijn accepts those for which the filter returns non-zero. 1165e6f30c73SWillem de Bruijn 1166e6f30c73SWillem de Bruijn To compile it as a module, choose M here. If unsure, say N. 1167e6f30c73SWillem de Bruijn 116882a37132SDaniel Borkmannconfig NETFILTER_XT_MATCH_CGROUP 116982a37132SDaniel Borkmann tristate '"control group" match support' 117082a37132SDaniel Borkmann depends on NETFILTER_ADVANCED 117182a37132SDaniel Borkmann depends on CGROUPS 11723ba0032aSMichal Koutný select SOCK_CGROUP_DATA 1173a7f7f624SMasahiro Yamada help 117482a37132SDaniel Borkmann Socket/process control group matching allows you to match locally 117582a37132SDaniel Borkmann generated packets based on which net_cls control group processes 117682a37132SDaniel Borkmann belong to. 117782a37132SDaniel Borkmann 11780269ea49SPablo Neira Ayusoconfig NETFILTER_XT_MATCH_CLUSTER 11790269ea49SPablo Neira Ayuso tristate '"cluster" match support' 11800269ea49SPablo Neira Ayuso depends on NF_CONNTRACK 11810269ea49SPablo Neira Ayuso depends on NETFILTER_ADVANCED 1182a7f7f624SMasahiro Yamada help 11830269ea49SPablo Neira Ayuso This option allows you to build work-load-sharing clusters of 11840269ea49SPablo Neira Ayuso network servers/stateful firewalls without having a dedicated 11850269ea49SPablo Neira Ayuso load-balancing router/server/switch. Basically, this match returns 11860269ea49SPablo Neira Ayuso true when the packet must be handled by this cluster node. Thus, 11870269ea49SPablo Neira Ayuso all nodes see all packets and this match decides which node handles 11880269ea49SPablo Neira Ayuso what packets. The work-load sharing algorithm is based on source 11890269ea49SPablo Neira Ayuso address hashing. 11900269ea49SPablo Neira Ayuso 11910269ea49SPablo Neira Ayuso If you say Y or M here, try `iptables -m cluster --help` for 11920269ea49SPablo Neira Ayuso more information. 11930269ea49SPablo Neira Ayuso 11942e4e6a17SHarald Welteconfig NETFILTER_XT_MATCH_COMMENT 11952e4e6a17SHarald Welte tristate '"comment" match support' 119633b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 11972e4e6a17SHarald Welte help 11982e4e6a17SHarald Welte This option adds a `comment' dummy-match, which allows you to put 11992e4e6a17SHarald Welte comments in your iptables ruleset. 12002e4e6a17SHarald Welte 12012e4e6a17SHarald Welte If you want to compile it as a module, say M here and read 1202cd238effSMauro Carvalho Chehab <file:Documentation/kbuild/modules.rst>. If unsure, say `N'. 12032e4e6a17SHarald Welte 12042e4e6a17SHarald Welteconfig NETFILTER_XT_MATCH_CONNBYTES 12052e4e6a17SHarald Welte tristate '"connbytes" per-connection counter match support' 1206587aa641SPatrick McHardy depends on NF_CONNTRACK 120733b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 12082e4e6a17SHarald Welte help 12092e4e6a17SHarald Welte This option adds a `connbytes' match, which allows you to match the 12102e4e6a17SHarald Welte number of bytes and/or packets for each direction within a connection. 12112e4e6a17SHarald Welte 12122e4e6a17SHarald Welte If you want to compile it as a module, say M here and read 1213cd238effSMauro Carvalho Chehab <file:Documentation/kbuild/modules.rst>. If unsure, say `N'. 12142e4e6a17SHarald Welte 1215c539f017SFlorian Westphalconfig NETFILTER_XT_MATCH_CONNLABEL 1216c539f017SFlorian Westphal tristate '"connlabel" match support' 1217c539f017SFlorian Westphal select NF_CONNTRACK_LABELS 121835612a22SFlorian Westphal depends on NF_CONNTRACK 1219c539f017SFlorian Westphal depends on NETFILTER_ADVANCED 1220a7f7f624SMasahiro Yamada help 1221c539f017SFlorian Westphal This match allows you to test and assign userspace-defined labels names 1222c539f017SFlorian Westphal to a connection. The kernel only stores bit values - mapping 1223c539f017SFlorian Westphal names to bits is done by userspace. 1224c539f017SFlorian Westphal 1225c539f017SFlorian Westphal Unlike connmark, more than 32 flag bits may be assigned to a 1226c539f017SFlorian Westphal connection simultaneously. 1227c539f017SFlorian Westphal 1228370786f9SJan Engelhardtconfig NETFILTER_XT_MATCH_CONNLIMIT 122948192248SRandy Dunlap tristate '"connlimit" match support' 12303fd8f9e4SCornelia Huck depends on NF_CONNTRACK 123133b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 1232625c5561SFlorian Westphal select NETFILTER_CONNCOUNT 1233a7f7f624SMasahiro Yamada help 1234370786f9SJan Engelhardt This match allows you to match against the number of parallel 1235370786f9SJan Engelhardt connections to a server per client IP address (or address block). 1236370786f9SJan Engelhardt 12372e4e6a17SHarald Welteconfig NETFILTER_XT_MATCH_CONNMARK 12382e4e6a17SHarald Welte tristate '"connmark" connection mark match support' 1239587aa641SPatrick McHardy depends on NF_CONNTRACK 124033b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 1241b8f00ba2SJan Engelhardt select NETFILTER_XT_CONNMARK 1242a7f7f624SMasahiro Yamada help 1243b8f00ba2SJan Engelhardt This is a backwards-compat option for the user's convenience 1244b8f00ba2SJan Engelhardt (e.g. when running oldconfig). It selects 1245b8f00ba2SJan Engelhardt CONFIG_NETFILTER_XT_CONNMARK (combined connmark/CONNMARK module). 12462e4e6a17SHarald Welte 12472e4e6a17SHarald Welteconfig NETFILTER_XT_MATCH_CONNTRACK 12482e4e6a17SHarald Welte tristate '"conntrack" connection tracking match support' 1249587aa641SPatrick McHardy depends on NF_CONNTRACK 125033b8e776SPatrick McHardy default m if NETFILTER_ADVANCED=n 12512e4e6a17SHarald Welte help 12522e4e6a17SHarald Welte This is a general conntrack match module, a superset of the state match. 12532e4e6a17SHarald Welte 12542e4e6a17SHarald Welte It allows matching on additional conntrack information, which is 12552e4e6a17SHarald Welte useful in complex configurations, such as NAT gateways with multiple 12562e4e6a17SHarald Welte internet links or tunnels. 12572e4e6a17SHarald Welte 12582e4e6a17SHarald Welte To compile it as a module, choose M here. If unsure, say N. 12592e4e6a17SHarald Welte 1260e8648a1fSEric Dumazetconfig NETFILTER_XT_MATCH_CPU 1261e8648a1fSEric Dumazet tristate '"cpu" match support' 1262e8648a1fSEric Dumazet depends on NETFILTER_ADVANCED 1263e8648a1fSEric Dumazet help 1264e8648a1fSEric Dumazet CPU matching allows you to match packets based on the CPU 1265e8648a1fSEric Dumazet currently handling the packet. 1266e8648a1fSEric Dumazet 1267e8648a1fSEric Dumazet To compile it as a module, choose M here. If unsure, say N. 1268e8648a1fSEric Dumazet 12692e4e6a17SHarald Welteconfig NETFILTER_XT_MATCH_DCCP 1270fd72f265SPablo Neira Ayuso tristate '"dccp" protocol match support (DEPRECATED)' 127133b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 1272fd72f265SPablo Neira Ayuso default n 12732e4e6a17SHarald Welte help 12742e4e6a17SHarald Welte With this option enabled, you will be able to use the iptables 12752e4e6a17SHarald Welte `dccp' match in order to match on DCCP source/destination ports 12762e4e6a17SHarald Welte and DCCP flags. 12772e4e6a17SHarald Welte 12782e4e6a17SHarald Welte If you want to compile it as a module, say M here and read 1279cd238effSMauro Carvalho Chehab <file:Documentation/kbuild/modules.rst>. If unsure, say `N'. 12802e4e6a17SHarald Welte 12819291747fSPatrick McHardyconfig NETFILTER_XT_MATCH_DEVGROUP 12829291747fSPatrick McHardy tristate '"devgroup" match support' 12839291747fSPatrick McHardy depends on NETFILTER_ADVANCED 12849291747fSPatrick McHardy help 12859291747fSPatrick McHardy This options adds a `devgroup' match, which allows to match on the 12869291747fSPatrick McHardy device group a network device is assigned to. 12879291747fSPatrick McHardy 12889291747fSPatrick McHardy To compile it as a module, choose M here. If unsure, say N. 12899291747fSPatrick McHardy 12909ba16276SYasuyuki Kozakaiconfig NETFILTER_XT_MATCH_DSCP 1291c3b33e6aSJan Engelhardt tristate '"dscp" and "tos" match support' 129233b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 12939ba16276SYasuyuki Kozakai help 12949ba16276SYasuyuki Kozakai This option adds a `DSCP' match, which allows you to match against 12959ba16276SYasuyuki Kozakai the IPv4/IPv6 header DSCP field (differentiated services codepoint). 12969ba16276SYasuyuki Kozakai 12979ba16276SYasuyuki Kozakai The DSCP field can have any value between 0x0 and 0x3f inclusive. 12989ba16276SYasuyuki Kozakai 1299c3b33e6aSJan Engelhardt It will also add a "tos" match, which allows you to match packets 1300c3b33e6aSJan Engelhardt based on the Type Of Service fields of the IPv4 packet (which share 1301c3b33e6aSJan Engelhardt the same bits as DSCP). 1302c3b33e6aSJan Engelhardt 13039ba16276SYasuyuki Kozakai To compile it as a module, choose M here. If unsure, say N. 13049ba16276SYasuyuki Kozakai 1305d446a820SJan Engelhardtconfig NETFILTER_XT_MATCH_ECN 1306d446a820SJan Engelhardt tristate '"ecn" match support' 1307d446a820SJan Engelhardt depends on NETFILTER_ADVANCED 1308a7f7f624SMasahiro Yamada help 1309d446a820SJan Engelhardt This option adds an "ECN" match, which allows you to match against 1310d446a820SJan Engelhardt the IPv4 and TCP header ECN fields. 1311d446a820SJan Engelhardt 1312d446a820SJan Engelhardt To compile it as a module, choose M here. If unsure, say N. 1313d446a820SJan Engelhardt 1314dc5ab2faSYasuyuki Kozakaiconfig NETFILTER_XT_MATCH_ESP 13154c37799cSJan Engelhardt tristate '"esp" match support' 131633b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 1317dc5ab2faSYasuyuki Kozakai help 1318dc5ab2faSYasuyuki Kozakai This match extension allows you to match a range of SPIs 1319dc5ab2faSYasuyuki Kozakai inside ESP header of IPSec packets. 1320dc5ab2faSYasuyuki Kozakai 1321dc5ab2faSYasuyuki Kozakai To compile it as a module, choose M here. If unsure, say N. 1322dc5ab2faSYasuyuki Kozakai 1323aba0d348SJan Engelhardtconfig NETFILTER_XT_MATCH_HASHLIMIT 1324aba0d348SJan Engelhardt tristate '"hashlimit" match support' 1325f09becc7SPablo Neira Ayuso depends on IP6_NF_IPTABLES || IP6_NF_IPTABLES=n 1326aba0d348SJan Engelhardt depends on NETFILTER_ADVANCED 1327aba0d348SJan Engelhardt help 1328aba0d348SJan Engelhardt This option adds a `hashlimit' match. 1329aba0d348SJan Engelhardt 1330aba0d348SJan Engelhardt As opposed to `limit', this match dynamically creates a hash table 1331aba0d348SJan Engelhardt of limit buckets, based on your selection of source/destination 1332aba0d348SJan Engelhardt addresses and/or ports. 1333aba0d348SJan Engelhardt 1334aba0d348SJan Engelhardt It enables you to express policies like `10kpps for any given 1335aba0d348SJan Engelhardt destination address' or `500pps from any given source address' 1336aba0d348SJan Engelhardt with a single rule. 1337aba0d348SJan Engelhardt 13382e4e6a17SHarald Welteconfig NETFILTER_XT_MATCH_HELPER 13392e4e6a17SHarald Welte tristate '"helper" match support' 1340587aa641SPatrick McHardy depends on NF_CONNTRACK 134133b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 13422e4e6a17SHarald Welte help 13432e4e6a17SHarald Welte Helper matching allows you to match packets in dynamic connections 134405ba4c89SYonatan Goldschmidt tracked by a conntrack-helper, ie. nf_conntrack_ftp 13452e4e6a17SHarald Welte 13462e4e6a17SHarald Welte To compile it as a module, choose M here. If unsure, say Y. 13472e4e6a17SHarald Welte 1348cfac5ef7SJan Engelhardtconfig NETFILTER_XT_MATCH_HL 1349cfac5ef7SJan Engelhardt tristate '"hl" hoplimit/TTL match support' 1350cfac5ef7SJan Engelhardt depends on NETFILTER_ADVANCED 1351a7f7f624SMasahiro Yamada help 1352cfac5ef7SJan Engelhardt HL matching allows you to match packets based on the hoplimit 1353cfac5ef7SJan Engelhardt in the IPv6 header, or the time-to-live field in the IPv4 1354cfac5ef7SJan Engelhardt header of the packet. 1355cfac5ef7SJan Engelhardt 13566a649f33Sfan.duconfig NETFILTER_XT_MATCH_IPCOMP 13576a649f33Sfan.du tristate '"ipcomp" match support' 13586a649f33Sfan.du depends on NETFILTER_ADVANCED 13596a649f33Sfan.du help 13606a649f33Sfan.du This match extension allows you to match a range of CPIs(16 bits) 13616a649f33Sfan.du inside IPComp header of IPSec packets. 13626a649f33Sfan.du 13636a649f33Sfan.du To compile it as a module, choose M here. If unsure, say N. 13646a649f33Sfan.du 1365f72e25a8SJan Engelhardtconfig NETFILTER_XT_MATCH_IPRANGE 1366f72e25a8SJan Engelhardt tristate '"iprange" address range match support' 1367f72e25a8SJan Engelhardt depends on NETFILTER_ADVANCED 1368a7f7f624SMasahiro Yamada help 1369f72e25a8SJan Engelhardt This option adds a "iprange" match, which allows you to match based on 1370f72e25a8SJan Engelhardt an IP address range. (Normal iptables only matches on single addresses 1371f72e25a8SJan Engelhardt with an optional mask.) 1372f72e25a8SJan Engelhardt 1373f72e25a8SJan Engelhardt If unsure, say M. 1374f72e25a8SJan Engelhardt 13759c3e1c39SHannes Ederconfig NETFILTER_XT_MATCH_IPVS 13769c3e1c39SHannes Eder tristate '"ipvs" match support' 13779c3e1c39SHannes Eder depends on IP_VS 13789c3e1c39SHannes Eder depends on NETFILTER_ADVANCED 13799c3e1c39SHannes Eder depends on NF_CONNTRACK 13809c3e1c39SHannes Eder help 13819c3e1c39SHannes Eder This option allows you to match against IPVS properties of a packet. 13829c3e1c39SHannes Eder 13839c3e1c39SHannes Eder If unsure, say N. 13849c3e1c39SHannes Eder 138574f77a6bSJames Chapmanconfig NETFILTER_XT_MATCH_L2TP 138674f77a6bSJames Chapman tristate '"l2tp" match support' 138774f77a6bSJames Chapman depends on NETFILTER_ADVANCED 138874f77a6bSJames Chapman default L2TP 1389a7f7f624SMasahiro Yamada help 139074f77a6bSJames Chapman This option adds an "L2TP" match, which allows you to match against 139174f77a6bSJames Chapman L2TP protocol header fields. 139274f77a6bSJames Chapman 139374f77a6bSJames Chapman To compile it as a module, choose M here. If unsure, say N. 139474f77a6bSJames Chapman 13952e4e6a17SHarald Welteconfig NETFILTER_XT_MATCH_LENGTH 13962e4e6a17SHarald Welte tristate '"length" match support' 139733b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 13982e4e6a17SHarald Welte help 13992e4e6a17SHarald Welte This option allows you to match the length of a packet against a 14002e4e6a17SHarald Welte specific value or range of values. 14012e4e6a17SHarald Welte 14022e4e6a17SHarald Welte To compile it as a module, choose M here. If unsure, say N. 14032e4e6a17SHarald Welte 14042e4e6a17SHarald Welteconfig NETFILTER_XT_MATCH_LIMIT 14052e4e6a17SHarald Welte tristate '"limit" match support' 140633b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 14072e4e6a17SHarald Welte help 14082e4e6a17SHarald Welte limit matching allows you to control the rate at which a rule can be 14092e4e6a17SHarald Welte matched: mainly useful in combination with the LOG target ("LOG 14102e4e6a17SHarald Welte target support", below) and to avoid some Denial of Service attacks. 14112e4e6a17SHarald Welte 14122e4e6a17SHarald Welte To compile it as a module, choose M here. If unsure, say N. 14132e4e6a17SHarald Welte 14142e4e6a17SHarald Welteconfig NETFILTER_XT_MATCH_MAC 14152e4e6a17SHarald Welte tristate '"mac" address match support' 141633b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 14172e4e6a17SHarald Welte help 14182e4e6a17SHarald Welte MAC matching allows you to match packets based on the source 14192e4e6a17SHarald Welte Ethernet address of the packet. 14202e4e6a17SHarald Welte 14212e4e6a17SHarald Welte To compile it as a module, choose M here. If unsure, say N. 14222e4e6a17SHarald Welte 14232e4e6a17SHarald Welteconfig NETFILTER_XT_MATCH_MARK 14242e4e6a17SHarald Welte tristate '"mark" match support' 142528b94988SJan Engelhardt depends on NETFILTER_ADVANCED 142628b94988SJan Engelhardt select NETFILTER_XT_MARK 1427a7f7f624SMasahiro Yamada help 142828b94988SJan Engelhardt This is a backwards-compat option for the user's convenience 142928b94988SJan Engelhardt (e.g. when running oldconfig). It selects 143028b94988SJan Engelhardt CONFIG_NETFILTER_XT_MARK (combined mark/MARK module). 14312e4e6a17SHarald Welte 1432aba0d348SJan Engelhardtconfig NETFILTER_XT_MATCH_MULTIPORT 1433aba0d348SJan Engelhardt tristate '"multiport" Multiple port match support' 1434aba0d348SJan Engelhardt depends on NETFILTER_ADVANCED 1435aba0d348SJan Engelhardt help 1436aba0d348SJan Engelhardt Multiport matching allows you to match TCP or UDP packets based on 1437aba0d348SJan Engelhardt a series of source or destination ports: normally a rule can only 1438aba0d348SJan Engelhardt match a single range of ports. 1439aba0d348SJan Engelhardt 1440aba0d348SJan Engelhardt To compile it as a module, choose M here. If unsure, say N. 1441aba0d348SJan Engelhardt 1442ceb98d03SPablo Neira Ayusoconfig NETFILTER_XT_MATCH_NFACCT 1443ceb98d03SPablo Neira Ayuso tristate '"nfacct" match support' 1444bc94b521SPablo Neira Ayuso depends on NETFILTER_ADVANCED 1445ceb98d03SPablo Neira Ayuso select NETFILTER_NETLINK_ACCT 1446ceb98d03SPablo Neira Ayuso help 1447ceb98d03SPablo Neira Ayuso This option allows you to use the extended accounting through 1448ceb98d03SPablo Neira Ayuso nfnetlink_acct. 1449ceb98d03SPablo Neira Ayuso 1450ceb98d03SPablo Neira Ayuso To compile it as a module, choose M here. If unsure, say N. 1451ceb98d03SPablo Neira Ayuso 1452115bc8f2SJan Engelhardtconfig NETFILTER_XT_MATCH_OSF 1453115bc8f2SJan Engelhardt tristate '"osf" Passive OS fingerprint match' 1454f6b7b5f4SFernando Fernandez Mancera depends on NETFILTER_ADVANCED 1455f6b7b5f4SFernando Fernandez Mancera select NETFILTER_NETLINK_OSF 1456115bc8f2SJan Engelhardt help 1457115bc8f2SJan Engelhardt This option selects the Passive OS Fingerprinting match module 1458115bc8f2SJan Engelhardt that allows to passively match the remote operating system by 1459115bc8f2SJan Engelhardt analyzing incoming TCP SYN packets. 1460115bc8f2SJan Engelhardt 1461115bc8f2SJan Engelhardt Rules and loading software can be downloaded from 1462115bc8f2SJan Engelhardt http://www.ioremap.net/projects/osf 1463115bc8f2SJan Engelhardt 1464115bc8f2SJan Engelhardt To compile it as a module, choose M here. If unsure, say N. 1465115bc8f2SJan Engelhardt 14660265ab44SJan Engelhardtconfig NETFILTER_XT_MATCH_OWNER 14670265ab44SJan Engelhardt tristate '"owner" match support' 146833b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 1469a7f7f624SMasahiro Yamada help 14700265ab44SJan Engelhardt Socket owner matching allows you to match locally-generated packets 14710265ab44SJan Engelhardt based on who created the socket: the user or group. It is also 14720265ab44SJan Engelhardt possible to check whether a socket actually exists. 14730265ab44SJan Engelhardt 1474c4b88513SPatrick McHardyconfig NETFILTER_XT_MATCH_POLICY 1475c4b88513SPatrick McHardy tristate 'IPsec "policy" match support' 1476c2df73deSJan Engelhardt depends on XFRM 147733b8e776SPatrick McHardy default m if NETFILTER_ADVANCED=n 1478c4b88513SPatrick McHardy help 1479c4b88513SPatrick McHardy Policy matching allows you to match packets based on the 1480c4b88513SPatrick McHardy IPsec policy that was used during decapsulation/will 1481c4b88513SPatrick McHardy be used during encapsulation. 1482c4b88513SPatrick McHardy 1483c4b88513SPatrick McHardy To compile it as a module, choose M here. If unsure, say N. 1484c4b88513SPatrick McHardy 14852e4e6a17SHarald Welteconfig NETFILTER_XT_MATCH_PHYSDEV 14862e4e6a17SHarald Welte tristate '"physdev" match support' 1487c2df73deSJan Engelhardt depends on BRIDGE && BRIDGE_NETFILTER 148833b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 14892e4e6a17SHarald Welte help 14902e4e6a17SHarald Welte Physdev packet matching matches against the physical bridge ports 14912e4e6a17SHarald Welte the IP packet arrived on or will leave by. 14922e4e6a17SHarald Welte 14932e4e6a17SHarald Welte To compile it as a module, choose M here. If unsure, say N. 14942e4e6a17SHarald Welte 14952e4e6a17SHarald Welteconfig NETFILTER_XT_MATCH_PKTTYPE 14962e4e6a17SHarald Welte tristate '"pkttype" packet type match support' 149733b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 14982e4e6a17SHarald Welte help 14992e4e6a17SHarald Welte Packet type matching allows you to match a packet by 15002e4e6a17SHarald Welte its "class", eg. BROADCAST, MULTICAST, ... 15012e4e6a17SHarald Welte 15022e4e6a17SHarald Welte Typical usage: 15032e4e6a17SHarald Welte iptables -A INPUT -m pkttype --pkt-type broadcast -j LOG 15042e4e6a17SHarald Welte 15052e4e6a17SHarald Welte To compile it as a module, choose M here. If unsure, say N. 15062e4e6a17SHarald Welte 150762b77434SPatrick McHardyconfig NETFILTER_XT_MATCH_QUOTA 150862b77434SPatrick McHardy tristate '"quota" match support' 150933b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 151062b77434SPatrick McHardy help 151162b77434SPatrick McHardy This option adds a `quota' match, which allows to match on a 151262b77434SPatrick McHardy byte counter. 151362b77434SPatrick McHardy 151462b77434SPatrick McHardy If you want to compile it as a module, say M here and read 1515cd238effSMauro Carvalho Chehab <file:Documentation/kbuild/modules.rst>. If unsure, say `N'. 151662b77434SPatrick McHardy 151750c164a8SPatrick McHardyconfig NETFILTER_XT_MATCH_RATEEST 151850c164a8SPatrick McHardy tristate '"rateest" match support' 1519b26e76b7SPatrick McHardy depends on NETFILTER_ADVANCED 152050c164a8SPatrick McHardy select NETFILTER_XT_TARGET_RATEEST 152150c164a8SPatrick McHardy help 152250c164a8SPatrick McHardy This option adds a `rateest' match, which allows to match on the 152350c164a8SPatrick McHardy rate estimated by the RATEEST target. 152450c164a8SPatrick McHardy 152550c164a8SPatrick McHardy To compile it as a module, choose M here. If unsure, say N. 152650c164a8SPatrick McHardy 15272e4e6a17SHarald Welteconfig NETFILTER_XT_MATCH_REALM 15282e4e6a17SHarald Welte tristate '"realm" match support' 152933b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 1530c7066f70SPatrick McHardy select IP_ROUTE_CLASSID 15312e4e6a17SHarald Welte help 15322e4e6a17SHarald Welte This option adds a `realm' match, which allows you to use the realm 15332e4e6a17SHarald Welte key from the routing subsystem inside iptables. 15342e4e6a17SHarald Welte 15352e4e6a17SHarald Welte This match pretty much resembles the CONFIG_NET_CLS_ROUTE4 option 15362e4e6a17SHarald Welte in tc world. 15372e4e6a17SHarald Welte 15382e4e6a17SHarald Welte If you want to compile it as a module, say M here and read 1539cd238effSMauro Carvalho Chehab <file:Documentation/kbuild/modules.rst>. If unsure, say `N'. 15402e4e6a17SHarald Welte 1541e948b20aSJan Engelhardtconfig NETFILTER_XT_MATCH_RECENT 1542e948b20aSJan Engelhardt tristate '"recent" match support' 1543e948b20aSJan Engelhardt depends on NETFILTER_ADVANCED 1544a7f7f624SMasahiro Yamada help 1545e948b20aSJan Engelhardt This match is used for creating one or many lists of recently 1546e948b20aSJan Engelhardt used addresses and then matching against that/those list(s). 1547e948b20aSJan Engelhardt 1548e948b20aSJan Engelhardt Short options are available by using 'iptables -m recent -h' 1549e948b20aSJan Engelhardt Official Website: <http://snowman.net/projects/ipt_recent/> 1550e948b20aSJan Engelhardt 15512e4e6a17SHarald Welteconfig NETFILTER_XT_MATCH_SCTP 1552663ef0d1SKees Cook tristate '"sctp" protocol match support' 155333b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 1554f3261affSPatrick McHardy default IP_SCTP 15552e4e6a17SHarald Welte help 15562e4e6a17SHarald Welte With this option enabled, you will be able to use the 15572e4e6a17SHarald Welte `sctp' match in order to match on SCTP source/destination ports 15582e4e6a17SHarald Welte and SCTP chunk types. 15592e4e6a17SHarald Welte 15602e4e6a17SHarald Welte If you want to compile it as a module, say M here and read 1561cd238effSMauro Carvalho Chehab <file:Documentation/kbuild/modules.rst>. If unsure, say `N'. 15622e4e6a17SHarald Welte 1563136cdc71SKOVACS Krisztianconfig NETFILTER_XT_MATCH_SOCKET 1564663ef0d1SKees Cook tristate '"socket" match support' 1565136cdc71SKOVACS Krisztian depends on NETFILTER_XTABLES 1566136cdc71SKOVACS Krisztian depends on NETFILTER_ADVANCED 1567f09becc7SPablo Neira Ayuso depends on IP6_NF_IPTABLES || IP6_NF_IPTABLES=n 15687414d929SMáté Eckl select NF_SOCKET_IPV4 15697414d929SMáté Eckl select NF_SOCKET_IPV6 if IP6_NF_IPTABLES 1570136cdc71SKOVACS Krisztian select NF_DEFRAG_IPV4 157174ec4d55SArnd Bergmann select NF_DEFRAG_IPV6 if IP6_NF_IPTABLES != n 1572136cdc71SKOVACS Krisztian help 1573136cdc71SKOVACS Krisztian This option adds a `socket' match, which can be used to match 1574136cdc71SKOVACS Krisztian packets for which a TCP or UDP socket lookup finds a valid socket. 1575136cdc71SKOVACS Krisztian It can be used in combination with the MARK target and policy 1576136cdc71SKOVACS Krisztian routing to implement full featured non-locally bound sockets. 1577136cdc71SKOVACS Krisztian 1578136cdc71SKOVACS Krisztian To compile it as a module, choose M here. If unsure, say N. 1579136cdc71SKOVACS Krisztian 15802e4e6a17SHarald Welteconfig NETFILTER_XT_MATCH_STATE 15812e4e6a17SHarald Welte tristate '"state" match support' 1582587aa641SPatrick McHardy depends on NF_CONNTRACK 158333b8e776SPatrick McHardy default m if NETFILTER_ADVANCED=n 15842e4e6a17SHarald Welte help 15852e4e6a17SHarald Welte Connection state matching allows you to match packets based on their 15862e4e6a17SHarald Welte relationship to a tracked connection (ie. previous packets). This 15872e4e6a17SHarald Welte is a powerful tool for packet classification. 15882e4e6a17SHarald Welte 15892e4e6a17SHarald Welte To compile it as a module, choose M here. If unsure, say N. 15902e4e6a17SHarald Welte 1591f3389805SPatrick McHardyconfig NETFILTER_XT_MATCH_STATISTIC 1592f3389805SPatrick McHardy tristate '"statistic" match support' 159333b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 1594f3389805SPatrick McHardy help 159568c1692eSPatrick McHardy This option adds a `statistic' match, which allows you to match 159668c1692eSPatrick McHardy on packets periodically or randomly with a given percentage. 159768c1692eSPatrick McHardy 159868c1692eSPatrick McHardy To compile it as a module, choose M here. If unsure, say N. 1599f3389805SPatrick McHardy 16002e4e6a17SHarald Welteconfig NETFILTER_XT_MATCH_STRING 16012e4e6a17SHarald Welte tristate '"string" match support' 160233b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 16032e4e6a17SHarald Welte select TEXTSEARCH 16042e4e6a17SHarald Welte select TEXTSEARCH_KMP 16052e4e6a17SHarald Welte select TEXTSEARCH_BM 16062e4e6a17SHarald Welte select TEXTSEARCH_FSM 16072e4e6a17SHarald Welte help 16082e4e6a17SHarald Welte This option adds a `string' match, which allows you to look for 16092e4e6a17SHarald Welte pattern matchings in packets. 16102e4e6a17SHarald Welte 16112e4e6a17SHarald Welte To compile it as a module, choose M here. If unsure, say N. 16122e4e6a17SHarald Welte 16132e4e6a17SHarald Welteconfig NETFILTER_XT_MATCH_TCPMSS 16142e4e6a17SHarald Welte tristate '"tcpmss" match support' 161533b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 16162e4e6a17SHarald Welte help 16172e4e6a17SHarald Welte This option adds a `tcpmss' match, which allows you to examine the 16182e4e6a17SHarald Welte MSS value of TCP SYN packets, which control the maximum packet size 16192e4e6a17SHarald Welte for that connection. 16202e4e6a17SHarald Welte 16212e4e6a17SHarald Welte To compile it as a module, choose M here. If unsure, say N. 16222e4e6a17SHarald Welte 1623ee4411a1SJan Engelhardtconfig NETFILTER_XT_MATCH_TIME 1624ee4411a1SJan Engelhardt tristate '"time" match support' 162533b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 1626a7f7f624SMasahiro Yamada help 1627ee4411a1SJan Engelhardt This option adds a "time" match, which allows you to match based on 1628ee4411a1SJan Engelhardt the packet arrival time (at the machine which netfilter is running) 1629ee4411a1SJan Engelhardt on) or departure time/date (for locally generated packets). 1630ee4411a1SJan Engelhardt 1631ee4411a1SJan Engelhardt If you say Y here, try `iptables -m time --help` for 1632ee4411a1SJan Engelhardt more information. 1633ee4411a1SJan Engelhardt 1634ee4411a1SJan Engelhardt If you want to compile it as a module, say M here. 1635ee4411a1SJan Engelhardt If unsure, say N. 1636ee4411a1SJan Engelhardt 16371b50b8a3SJan Engelhardtconfig NETFILTER_XT_MATCH_U32 16381b50b8a3SJan Engelhardt tristate '"u32" match support' 163933b8e776SPatrick McHardy depends on NETFILTER_ADVANCED 1640a7f7f624SMasahiro Yamada help 16411b50b8a3SJan Engelhardt u32 allows you to extract quantities of up to 4 bytes from a packet, 16421b50b8a3SJan Engelhardt AND them with specified masks, shift them by specified amounts and 16431b50b8a3SJan Engelhardt test whether the results are in any of a set of specified ranges. 16441b50b8a3SJan Engelhardt The specification of what to extract is general enough to skip over 16451b50b8a3SJan Engelhardt headers with lengths stored in the packet, as in IP or TCP header 16461b50b8a3SJan Engelhardt lengths. 16471b50b8a3SJan Engelhardt 16481b50b8a3SJan Engelhardt Details and examples are in the kernel module source. 16491b50b8a3SJan Engelhardt 1650c2df73deSJan Engelhardtendif # NETFILTER_XTABLES 1651a6c1cd57SHarald Welte 1652403cec8aSFlorian Westphalconfig GCOV_PROFILE_NETFILTER 1653403cec8aSFlorian Westphal bool "Enable GCOV profiling for netfilter" 1654403cec8aSFlorian Westphal depends on GCOV_KERNEL 1655403cec8aSFlorian Westphal help 1656403cec8aSFlorian Westphal Enable GCOV profiling for netfilter to check which functions/lines 1657403cec8aSFlorian Westphal are executed. 1658403cec8aSFlorian Westphal 1659403cec8aSFlorian Westphal If unsure, say N. 1660c2df73deSJan Engelhardtendmenu 1661f9e815b3SHarald Welte 1662a7b4f989SJozsef Kadlecsiksource "net/netfilter/ipset/Kconfig" 1663a7b4f989SJozsef Kadlecsik 1664cb7f6a7bSJulius Volzsource "net/netfilter/ipvs/Kconfig" 1665