1# 2# IP netfilter configuration 3# 4 5menu "IP: Netfilter Configuration" 6 depends on INET && NETFILTER 7 8config NF_DEFRAG_IPV4 9 tristate 10 default n 11 12config NF_SOCKET_IPV4 13 tristate "IPv4 socket lookup support" 14 help 15 This option enables the IPv4 socket lookup infrastructure. This is 16 is required by the {ip,nf}tables socket match. 17 18config NF_TPROXY_IPV4 19 tristate "IPv4 tproxy support" 20 21if NF_TABLES 22 23config NF_TABLES_IPV4 24 bool "IPv4 nf_tables support" 25 help 26 This option enables the IPv4 support for nf_tables. 27 28if NF_TABLES_IPV4 29 30config NFT_CHAIN_ROUTE_IPV4 31 tristate "IPv4 nf_tables route chain support" 32 help 33 This option enables the "route" chain for IPv4 in nf_tables. This 34 chain type is used to force packet re-routing after mangling header 35 fields such as the source, destination, type of service and 36 the packet mark. 37 38config NFT_REJECT_IPV4 39 select NF_REJECT_IPV4 40 default NFT_REJECT 41 tristate 42 43config NFT_DUP_IPV4 44 tristate "IPv4 nf_tables packet duplication support" 45 depends on !NF_CONNTRACK || NF_CONNTRACK 46 select NF_DUP_IPV4 47 help 48 This module enables IPv4 packet duplication support for nf_tables. 49 50config NFT_FIB_IPV4 51 select NFT_FIB 52 tristate "nf_tables fib / ip route lookup support" 53 help 54 This module enables IPv4 FIB lookups, e.g. for reverse path filtering. 55 It also allows query of the FIB for the route type, e.g. local, unicast, 56 multicast or blackhole. 57 58endif # NF_TABLES_IPV4 59 60config NF_TABLES_ARP 61 bool "ARP nf_tables support" 62 select NETFILTER_FAMILY_ARP 63 help 64 This option enables the ARP support for nf_tables. 65 66endif # NF_TABLES 67 68config NF_FLOW_TABLE_IPV4 69 tristate "Netfilter flow table IPv4 module" 70 depends on NF_FLOW_TABLE 71 help 72 This option adds the flow table IPv4 support. 73 74 To compile it as a module, choose M here. 75 76config NF_DUP_IPV4 77 tristate "Netfilter IPv4 packet duplication to alternate destination" 78 depends on !NF_CONNTRACK || NF_CONNTRACK 79 help 80 This option enables the nf_dup_ipv4 core, which duplicates an IPv4 81 packet to be rerouted to another destination. 82 83config NF_LOG_ARP 84 tristate "ARP packet logging" 85 default m if NETFILTER_ADVANCED=n 86 select NF_LOG_COMMON 87 88config NF_LOG_IPV4 89 tristate "IPv4 packet logging" 90 default m if NETFILTER_ADVANCED=n 91 select NF_LOG_COMMON 92 93config NF_REJECT_IPV4 94 tristate "IPv4 packet rejection" 95 default m if NETFILTER_ADVANCED=n 96 97if NF_NAT 98 99if NF_TABLES 100config NFT_CHAIN_NAT_IPV4 101 depends on NF_TABLES_IPV4 102 tristate "IPv4 nf_tables nat chain support" 103 help 104 This option enables the "nat" chain for IPv4 in nf_tables. This 105 chain type is used to perform Network Address Translation (NAT) 106 packet transformations such as the source, destination address and 107 source and destination ports. 108 109endif # NF_TABLES 110 111config NF_NAT_SNMP_BASIC 112 tristate "Basic SNMP-ALG support" 113 depends on NF_CONNTRACK_SNMP 114 depends on NETFILTER_ADVANCED 115 default NF_NAT && NF_CONNTRACK_SNMP 116 select ASN1 117 ---help--- 118 119 This module implements an Application Layer Gateway (ALG) for 120 SNMP payloads. In conjunction with NAT, it allows a network 121 management system to access multiple private networks with 122 conflicting addresses. It works by modifying IP addresses 123 inside SNMP payloads to match IP-layer NAT mapping. 124 125 This is the "basic" form of SNMP-ALG, as described in RFC 2962 126 127 To compile it as a module, choose M here. If unsure, say N. 128 129config NF_NAT_PPTP 130 tristate 131 depends on NF_CONNTRACK 132 default NF_CONNTRACK_PPTP 133 134config NF_NAT_H323 135 tristate 136 depends on NF_CONNTRACK 137 default NF_CONNTRACK_H323 138 139endif # NF_NAT 140 141config IP_NF_IPTABLES 142 tristate "IP tables support (required for filtering/masq/NAT)" 143 default m if NETFILTER_ADVANCED=n 144 select NETFILTER_XTABLES 145 help 146 iptables is a general, extensible packet identification framework. 147 The packet filtering and full NAT (masquerading, port forwarding, 148 etc) subsystems now use this: say `Y' or `M' here if you want to use 149 either of those. 150 151 To compile it as a module, choose M here. If unsure, say N. 152 153if IP_NF_IPTABLES 154 155# The matches. 156config IP_NF_MATCH_AH 157 tristate '"ah" match support' 158 depends on NETFILTER_ADVANCED 159 help 160 This match extension allows you to match a range of SPIs 161 inside AH header of IPSec packets. 162 163 To compile it as a module, choose M here. If unsure, say N. 164 165config IP_NF_MATCH_ECN 166 tristate '"ecn" match support' 167 depends on NETFILTER_ADVANCED 168 select NETFILTER_XT_MATCH_ECN 169 ---help--- 170 This is a backwards-compat option for the user's convenience 171 (e.g. when running oldconfig). It selects 172 CONFIG_NETFILTER_XT_MATCH_ECN. 173 174config IP_NF_MATCH_RPFILTER 175 tristate '"rpfilter" reverse path filter match support' 176 depends on NETFILTER_ADVANCED 177 depends on IP_NF_MANGLE || IP_NF_RAW 178 ---help--- 179 This option allows you to match packets whose replies would 180 go out via the interface the packet came in. 181 182 To compile it as a module, choose M here. If unsure, say N. 183 The module will be called ipt_rpfilter. 184 185config IP_NF_MATCH_TTL 186 tristate '"ttl" match support' 187 depends on NETFILTER_ADVANCED 188 select NETFILTER_XT_MATCH_HL 189 ---help--- 190 This is a backwards-compat option for the user's convenience 191 (e.g. when running oldconfig). It selects 192 CONFIG_NETFILTER_XT_MATCH_HL. 193 194# `filter', generic and specific targets 195config IP_NF_FILTER 196 tristate "Packet filtering" 197 default m if NETFILTER_ADVANCED=n 198 help 199 Packet filtering defines a table `filter', which has a series of 200 rules for simple packet filtering at local input, forwarding and 201 local output. See the man page for iptables(8). 202 203 To compile it as a module, choose M here. If unsure, say N. 204 205config IP_NF_TARGET_REJECT 206 tristate "REJECT target support" 207 depends on IP_NF_FILTER 208 select NF_REJECT_IPV4 209 default m if NETFILTER_ADVANCED=n 210 help 211 The REJECT target allows a filtering rule to specify that an ICMP 212 error should be issued in response to an incoming packet, rather 213 than silently being dropped. 214 215 To compile it as a module, choose M here. If unsure, say N. 216 217config IP_NF_TARGET_SYNPROXY 218 tristate "SYNPROXY target support" 219 depends on NF_CONNTRACK && NETFILTER_ADVANCED 220 select NETFILTER_SYNPROXY 221 select SYN_COOKIES 222 help 223 The SYNPROXY target allows you to intercept TCP connections and 224 establish them using syncookies before they are passed on to the 225 server. This allows to avoid conntrack and server resource usage 226 during SYN-flood attacks. 227 228 To compile it as a module, choose M here. If unsure, say N. 229 230# NAT + specific targets: nf_conntrack 231config IP_NF_NAT 232 tristate "iptables NAT support" 233 depends on NF_CONNTRACK 234 default m if NETFILTER_ADVANCED=n 235 select NF_NAT 236 select NETFILTER_XT_NAT 237 help 238 This enables the `nat' table in iptables. This allows masquerading, 239 port forwarding and other forms of full Network Address Port 240 Translation. 241 242 To compile it as a module, choose M here. If unsure, say N. 243 244if IP_NF_NAT 245 246config IP_NF_TARGET_MASQUERADE 247 tristate "MASQUERADE target support" 248 select NF_NAT_MASQUERADE 249 default m if NETFILTER_ADVANCED=n 250 help 251 Masquerading is a special case of NAT: all outgoing connections are 252 changed to seem to come from a particular interface's address, and 253 if the interface goes down, those connections are lost. This is 254 only useful for dialup accounts with dynamic IP address (ie. your IP 255 address will be different on next dialup). 256 257 To compile it as a module, choose M here. If unsure, say N. 258 259config IP_NF_TARGET_NETMAP 260 tristate "NETMAP target support" 261 depends on NETFILTER_ADVANCED 262 select NETFILTER_XT_TARGET_NETMAP 263 ---help--- 264 This is a backwards-compat option for the user's convenience 265 (e.g. when running oldconfig). It selects 266 CONFIG_NETFILTER_XT_TARGET_NETMAP. 267 268config IP_NF_TARGET_REDIRECT 269 tristate "REDIRECT target support" 270 depends on NETFILTER_ADVANCED 271 select NETFILTER_XT_TARGET_REDIRECT 272 ---help--- 273 This is a backwards-compat option for the user's convenience 274 (e.g. when running oldconfig). It selects 275 CONFIG_NETFILTER_XT_TARGET_REDIRECT. 276 277endif # IP_NF_NAT 278 279# mangle + specific targets 280config IP_NF_MANGLE 281 tristate "Packet mangling" 282 default m if NETFILTER_ADVANCED=n 283 help 284 This option adds a `mangle' table to iptables: see the man page for 285 iptables(8). This table is used for various packet alterations 286 which can effect how the packet is routed. 287 288 To compile it as a module, choose M here. If unsure, say N. 289 290config IP_NF_TARGET_CLUSTERIP 291 tristate "CLUSTERIP target support" 292 depends on IP_NF_MANGLE 293 depends on NF_CONNTRACK 294 depends on NETFILTER_ADVANCED 295 select NF_CONNTRACK_MARK 296 select NETFILTER_FAMILY_ARP 297 help 298 The CLUSTERIP target allows you to build load-balancing clusters of 299 network servers without having a dedicated load-balancing 300 router/server/switch. 301 302 To compile it as a module, choose M here. If unsure, say N. 303 304config IP_NF_TARGET_ECN 305 tristate "ECN target support" 306 depends on IP_NF_MANGLE 307 depends on NETFILTER_ADVANCED 308 ---help--- 309 This option adds a `ECN' target, which can be used in the iptables mangle 310 table. 311 312 You can use this target to remove the ECN bits from the IPv4 header of 313 an IP packet. This is particularly useful, if you need to work around 314 existing ECN blackholes on the internet, but don't want to disable 315 ECN support in general. 316 317 To compile it as a module, choose M here. If unsure, say N. 318 319config IP_NF_TARGET_TTL 320 tristate '"TTL" target support' 321 depends on NETFILTER_ADVANCED && IP_NF_MANGLE 322 select NETFILTER_XT_TARGET_HL 323 ---help--- 324 This is a backwards-compatible option for the user's convenience 325 (e.g. when running oldconfig). It selects 326 CONFIG_NETFILTER_XT_TARGET_HL. 327 328# raw + specific targets 329config IP_NF_RAW 330 tristate 'raw table support (required for NOTRACK/TRACE)' 331 help 332 This option adds a `raw' table to iptables. This table is the very 333 first in the netfilter framework and hooks in at the PREROUTING 334 and OUTPUT chains. 335 336 If you want to compile it as a module, say M here and read 337 <file:Documentation/kbuild/modules.txt>. If unsure, say `N'. 338 339# security table for MAC policy 340config IP_NF_SECURITY 341 tristate "Security table" 342 depends on SECURITY 343 depends on NETFILTER_ADVANCED 344 help 345 This option adds a `security' table to iptables, for use 346 with Mandatory Access Control (MAC) policy. 347 348 If unsure, say N. 349 350endif # IP_NF_IPTABLES 351 352# ARP tables 353config IP_NF_ARPTABLES 354 tristate "ARP tables support" 355 select NETFILTER_XTABLES 356 select NETFILTER_FAMILY_ARP 357 depends on NETFILTER_ADVANCED 358 help 359 arptables is a general, extensible packet identification framework. 360 The ARP packet filtering and mangling (manipulation)subsystems 361 use this: say Y or M here if you want to use either of those. 362 363 To compile it as a module, choose M here. If unsure, say N. 364 365if IP_NF_ARPTABLES 366 367config IP_NF_ARPFILTER 368 tristate "ARP packet filtering" 369 help 370 ARP packet filtering defines a table `filter', which has a series of 371 rules for simple ARP packet filtering at local input and 372 local output. On a bridge, you can also specify filtering rules 373 for forwarded ARP packets. See the man page for arptables(8). 374 375 To compile it as a module, choose M here. If unsure, say N. 376 377config IP_NF_ARP_MANGLE 378 tristate "ARP payload mangling" 379 help 380 Allows altering the ARP packet payload: source and destination 381 hardware and network addresses. 382 383endif # IP_NF_ARPTABLES 384 385endmenu 386 387