summaryrefslogtreecommitdiffstats
path: root/net
diff options
context:
space:
mode:
authorFlorian Westphal <fw@strlen.de>2017-07-07 13:29:03 +0200
committerPablo Neira Ayuso <pablo@netfilter.org>2017-07-17 17:02:44 +0200
commit974292defee033bc43ccfcb2fcefc3eba3905340 (patch)
treef9865fb83ea6979a8f7ef02d10020af01090e3bb /net
parent97772bcd56efa21d9d8976db6f205574ea602f51 (diff)
downloadlinux-974292defee033bc43ccfcb2fcefc3eba3905340.tar.gz
linux-974292defee033bc43ccfcb2fcefc3eba3905340.tar.bz2
linux-974292defee033bc43ccfcb2fcefc3eba3905340.zip
netfilter: nf_tables: only allow in/output for arp packets
arp packets cannot be forwarded. They can be bridged, but then they can be filtered using either ebtables or nftables bridge family. The bridge netfilter exposes a "call-arptables" switch which pushes packets into arptables, but lets not expose this for nftables, so better close this asap. Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'net')
-rw-r--r--net/ipv4/netfilter/nf_tables_arp.c3
1 files changed, 1 insertions, 2 deletions
diff --git a/net/ipv4/netfilter/nf_tables_arp.c b/net/ipv4/netfilter/nf_tables_arp.c
index 805c8ddfe860..4bbc273b45e8 100644
--- a/net/ipv4/netfilter/nf_tables_arp.c
+++ b/net/ipv4/netfilter/nf_tables_arp.c
@@ -72,8 +72,7 @@ static const struct nf_chain_type filter_arp = {
.family = NFPROTO_ARP,
.owner = THIS_MODULE,
.hook_mask = (1 << NF_ARP_IN) |
- (1 << NF_ARP_OUT) |
- (1 << NF_ARP_FORWARD),
+ (1 << NF_ARP_OUT),
};
static int __init nf_tables_arp_init(void)