netfilter: ipset: hash:net,iface type introduced
authorJozsef Kadlecsik <kadlec@blackhole.kfki.hu>
Thu, 16 Jun 2011 17:00:48 +0000 (19:00 +0200)
committerPatrick McHardy <kaber@trash.net>
Thu, 16 Jun 2011 17:00:48 +0000 (19:00 +0200)
commite385357a2f214e4d4e79c6118f1bede2572e0701
tree22ec359f9c9dc8b2ba290383a80663a5ea9f705a
parent9b03a5ef49c01515387133ac5bd47073fae56318
netfilter: ipset: hash:net,iface type introduced

The hash:net,iface type makes possible to store network address and
interface name pairs in a set. It's mostly suitable for egress
and ingress filtering. Examples:

        # ipset create test hash:net,iface
        # ipset add test 192.168.0.0/16,eth0
        # ipset add test 192.168.0.0/24,eth1

Signed-off-by: Jozsef Kadlecsik <kadlec@blackhole.kfki.hu>
Signed-off-by: Patrick McHardy <kaber@trash.net>
include/linux/netfilter/ipset/ip_set.h
include/linux/netfilter/ipset/ip_set_ahash.h
net/netfilter/ipset/Kconfig
net/netfilter/ipset/Makefile
net/netfilter/ipset/ip_set_hash_netiface.c [new file with mode: 0644]