1# SPDX-License-Identifier: GPL-2.0-only 2menu "Core Netfilter Configuration" 3 depends on INET && NETFILTER 4 5config NETFILTER_INGRESS 6 bool "Netfilter ingress support" 7 default y 8 select NET_INGRESS 9 help 10 This allows you to classify packets from ingress using the Netfilter 11 infrastructure. 12 13config NETFILTER_NETLINK 14 tristate 15 16config NETFILTER_FAMILY_BRIDGE 17 bool 18 19config NETFILTER_FAMILY_ARP 20 bool 21 22config NETFILTER_NETLINK_ACCT 23 tristate "Netfilter NFACCT over NFNETLINK interface" 24 depends on NETFILTER_ADVANCED 25 select NETFILTER_NETLINK 26 help 27 If this option is enabled, the kernel will include support 28 for extended accounting via NFNETLINK. 29 30config NETFILTER_NETLINK_QUEUE 31 tristate "Netfilter NFQUEUE over NFNETLINK interface" 32 depends on NETFILTER_ADVANCED 33 select NETFILTER_NETLINK 34 help 35 If this option is enabled, the kernel will include support 36 for queueing packets via NFNETLINK. 37 38config NETFILTER_NETLINK_LOG 39 tristate "Netfilter LOG over NFNETLINK interface" 40 default m if NETFILTER_ADVANCED=n 41 select NETFILTER_NETLINK 42 help 43 If this option is enabled, the kernel will include support 44 for logging packets via NFNETLINK. 45 46 This obsoletes the existing ipt_ULOG and ebg_ulog mechanisms, 47 and is also scheduled to replace the old syslog-based ipt_LOG 48 and ip6t_LOG modules. 49 50config NETFILTER_NETLINK_OSF 51 tristate "Netfilter OSF over NFNETLINK interface" 52 depends on NETFILTER_ADVANCED 53 select NETFILTER_NETLINK 54 help 55 If this option is enabled, the kernel will include support 56 for passive OS fingerprint via NFNETLINK. 57 58config NF_CONNTRACK 59 tristate "Netfilter connection tracking support" 60 default m if NETFILTER_ADVANCED=n 61 select NF_DEFRAG_IPV4 62 select NF_DEFRAG_IPV6 if IPV6 != n 63 help 64 Connection tracking keeps a record of what packets have passed 65 through your machine, in order to figure out how they are related 66 into connections. 67 68 This is required to do Masquerading or other kinds of Network 69 Address Translation. It can also be used to enhance packet 70 filtering (see `Connection state match support' below). 71 72 To compile it as a module, choose M here. If unsure, say N. 73 74config NF_LOG_COMMON 75 tristate 76 77config NF_LOG_NETDEV 78 tristate "Netdev packet logging" 79 select NF_LOG_COMMON 80 81config NF_LOG_SYSLOG 82 tristate "Syslog packet logging" 83 default m if NETFILTER_ADVANCED=n 84 select NF_LOG_COMMON 85 help 86 This option enable support for packet logging via syslog. 87 It supports IPv4 and common transport protocols such as TCP and UDP. 88 This is a simpler but less flexible logging method compared to 89 CONFIG_NETFILTER_NETLINK_LOG. 90 If both are enabled the backend to use can be configured at run-time 91 by means of per-address-family sysctl tunables. 92 93if NF_CONNTRACK 94config NETFILTER_CONNCOUNT 95 tristate 96 97config NF_CONNTRACK_MARK 98 bool 'Connection mark tracking support' 99 depends on NETFILTER_ADVANCED 100 help 101 This option enables support for connection marks, used by the 102 `CONNMARK' target and `connmark' match. Similar to the mark value 103 of packets, but this mark value is kept in the conntrack session 104 instead of the individual packets. 105 106config NF_CONNTRACK_SECMARK 107 bool 'Connection tracking security mark support' 108 depends on NETWORK_SECMARK 109 default m if NETFILTER_ADVANCED=n 110 help 111 This option enables security markings to be applied to 112 connections. Typically they are copied to connections from 113 packets using the CONNSECMARK target and copied back from 114 connections to packets with the same target, with the packets 115 being originally labeled via SECMARK. 116 117 If unsure, say 'N'. 118 119config NF_CONNTRACK_ZONES 120 bool 'Connection tracking zones' 121 depends on NETFILTER_ADVANCED 122 help 123 This option enables support for connection tracking zones. 124 Normally, each connection needs to have a unique system wide 125 identity. Connection tracking zones allow to have multiple 126 connections using the same identity, as long as they are 127 contained in different zones. 128 129 If unsure, say `N'. 130 131config NF_CONNTRACK_PROCFS 132 bool "Supply CT list in procfs (OBSOLETE)" 133 default y 134 depends on PROC_FS 135 help 136 This option enables for the list of known conntrack entries 137 to be shown in procfs under net/netfilter/nf_conntrack. This 138 is considered obsolete in favor of using the conntrack(8) 139 tool which uses Netlink. 140 141config NF_CONNTRACK_EVENTS 142 bool "Connection tracking events" 143 depends on NETFILTER_ADVANCED 144 help 145 If this option is enabled, the connection tracking code will 146 provide a notifier chain that can be used by other kernel code 147 to get notified about changes in the connection tracking state. 148 149 If unsure, say `N'. 150 151config NF_CONNTRACK_TIMEOUT 152 bool 'Connection tracking timeout' 153 depends on NETFILTER_ADVANCED 154 help 155 This option enables support for connection tracking timeout 156 extension. This allows you to attach timeout policies to flow 157 via the CT target. 158 159 If unsure, say `N'. 160 161config NF_CONNTRACK_TIMESTAMP 162 bool 'Connection tracking timestamping' 163 depends on NETFILTER_ADVANCED 164 help 165 This option enables support for connection tracking timestamping. 166 This allows you to store the flow start-time and to obtain 167 the flow-stop time (once it has been destroyed) via Connection 168 tracking events. 169 170 If unsure, say `N'. 171 172config NF_CONNTRACK_LABELS 173 bool "Connection tracking labels" 174 help 175 This option enables support for assigning user-defined flag bits 176 to connection tracking entries. It can be used with xtables connlabel 177 match and the nftables ct expression. 178 179config NF_CT_PROTO_DCCP 180 bool 'DCCP protocol connection tracking support' 181 depends on NETFILTER_ADVANCED 182 default y 183 help 184 With this option enabled, the layer 3 independent connection 185 tracking code will be able to do state tracking on DCCP connections. 186 187 If unsure, say Y. 188 189config NF_CT_PROTO_GRE 190 bool 191 192config NF_CT_PROTO_SCTP 193 bool 'SCTP protocol connection tracking support' 194 depends on NETFILTER_ADVANCED 195 default y 196 select LIBCRC32C 197 help 198 With this option enabled, the layer 3 independent connection 199 tracking code will be able to do state tracking on SCTP connections. 200 201 If unsure, say Y. 202 203config NF_CT_PROTO_UDPLITE 204 bool 'UDP-Lite protocol connection tracking support' 205 depends on NETFILTER_ADVANCED 206 default y 207 help 208 With this option enabled, the layer 3 independent connection 209 tracking code will be able to do state tracking on UDP-Lite 210 connections. 211 212 If unsure, say Y. 213 214config NF_CONNTRACK_AMANDA 215 tristate "Amanda backup protocol support" 216 depends on NETFILTER_ADVANCED 217 select TEXTSEARCH 218 select TEXTSEARCH_KMP 219 help 220 If you are running the Amanda backup package <http://www.amanda.org/> 221 on this machine or machines that will be MASQUERADED through this 222 machine, then you may want to enable this feature. This allows the 223 connection tracking and natting code to allow the sub-channels that 224 Amanda requires for communication of the backup data, messages and 225 index. 226 227 To compile it as a module, choose M here. If unsure, say N. 228 229config NF_CONNTRACK_FTP 230 tristate "FTP protocol support" 231 default m if NETFILTER_ADVANCED=n 232 help 233 Tracking FTP connections is problematic: special helpers are 234 required for tracking them, and doing masquerading and other forms 235 of Network Address Translation on them. 236 237 This is FTP support on Layer 3 independent connection tracking. 238 239 To compile it as a module, choose M here. If unsure, say N. 240 241config NF_CONNTRACK_H323 242 tristate "H.323 protocol support" 243 depends on IPV6 || IPV6=n 244 depends on NETFILTER_ADVANCED 245 help 246 H.323 is a VoIP signalling protocol from ITU-T. As one of the most 247 important VoIP protocols, it is widely used by voice hardware and 248 software including voice gateways, IP phones, Netmeeting, OpenPhone, 249 Gnomemeeting, etc. 250 251 With this module you can support H.323 on a connection tracking/NAT 252 firewall. 253 254 This module supports RAS, Fast Start, H.245 Tunnelling, Call 255 Forwarding, RTP/RTCP and T.120 based audio, video, fax, chat, 256 whiteboard, file transfer, etc. For more information, please 257 visit http://nath323.sourceforge.net/. 258 259 To compile it as a module, choose M here. If unsure, say N. 260 261config NF_CONNTRACK_IRC 262 tristate "IRC protocol support" 263 default m if NETFILTER_ADVANCED=n 264 help 265 There is a commonly-used extension to IRC called 266 Direct Client-to-Client Protocol (DCC). This enables users to send 267 files to each other, and also chat to each other without the need 268 of a server. DCC Sending is used anywhere you send files over IRC, 269 and DCC Chat is most commonly used by Eggdrop bots. If you are 270 using NAT, this extension will enable you to send files and initiate 271 chats. Note that you do NOT need this extension to get files or 272 have others initiate chats, or everything else in IRC. 273 274 To compile it as a module, choose M here. If unsure, say N. 275 276config NF_CONNTRACK_BROADCAST 277 tristate 278 279config NF_CONNTRACK_NETBIOS_NS 280 tristate "NetBIOS name service protocol support" 281 select NF_CONNTRACK_BROADCAST 282 help 283 NetBIOS name service requests are sent as broadcast messages from an 284 unprivileged port and responded to with unicast messages to the 285 same port. This make them hard to firewall properly because connection 286 tracking doesn't deal with broadcasts. This helper tracks locally 287 originating NetBIOS name service requests and the corresponding 288 responses. It relies on correct IP address configuration, specifically 289 netmask and broadcast address. When properly configured, the output 290 of "ip address show" should look similar to this: 291 292 $ ip -4 address show eth0 293 4: eth0: <BROADCAST,MULTICAST,UP> mtu 1500 qdisc pfifo_fast qlen 1000 294 inet 172.16.2.252/24 brd 172.16.2.255 scope global eth0 295 296 To compile it as a module, choose M here. If unsure, say N. 297 298config NF_CONNTRACK_SNMP 299 tristate "SNMP service protocol support" 300 depends on NETFILTER_ADVANCED 301 select NF_CONNTRACK_BROADCAST 302 help 303 SNMP service requests are sent as broadcast messages from an 304 unprivileged port and responded to with unicast messages to the 305 same port. This make them hard to firewall properly because connection 306 tracking doesn't deal with broadcasts. This helper tracks locally 307 originating SNMP service requests and the corresponding 308 responses. It relies on correct IP address configuration, specifically 309 netmask and broadcast address. 310 311 To compile it as a module, choose M here. If unsure, say N. 312 313config NF_CONNTRACK_PPTP 314 tristate "PPtP protocol support" 315 depends on NETFILTER_ADVANCED 316 select NF_CT_PROTO_GRE 317 help 318 This module adds support for PPTP (Point to Point Tunnelling 319 Protocol, RFC2637) connection tracking and NAT. 320 321 If you are running PPTP sessions over a stateful firewall or NAT 322 box, you may want to enable this feature. 323 324 Please note that not all PPTP modes of operation are supported yet. 325 Specifically these limitations exist: 326 - Blindly assumes that control connections are always established 327 in PNS->PAC direction. This is a violation of RFC2637. 328 - Only supports a single call within each session 329 330 To compile it as a module, choose M here. If unsure, say N. 331 332config NF_CONNTRACK_SANE 333 tristate "SANE protocol support" 334 depends on NETFILTER_ADVANCED 335 help 336 SANE is a protocol for remote access to scanners as implemented 337 by the 'saned' daemon. Like FTP, it uses separate control and 338 data connections. 339 340 With this module you can support SANE on a connection tracking 341 firewall. 342 343 To compile it as a module, choose M here. If unsure, say N. 344 345config NF_CONNTRACK_SIP 346 tristate "SIP protocol support" 347 default m if NETFILTER_ADVANCED=n 348 help 349 SIP is an application-layer control protocol that can establish, 350 modify, and terminate multimedia sessions (conferences) such as 351 Internet telephony calls. With the nf_conntrack_sip and 352 the nf_nat_sip modules you can support the protocol on a connection 353 tracking/NATing firewall. 354 355 To compile it as a module, choose M here. If unsure, say N. 356 357config NF_CONNTRACK_TFTP 358 tristate "TFTP protocol support" 359 depends on NETFILTER_ADVANCED 360 help 361 TFTP connection tracking helper, this is required depending 362 on how restrictive your ruleset is. 363 If you are using a tftp client behind -j SNAT or -j MASQUERADING 364 you will need this. 365 366 To compile it as a module, choose M here. If unsure, say N. 367 368config NF_CT_NETLINK 369 tristate 'Connection tracking netlink interface' 370 select NETFILTER_NETLINK 371 default m if NETFILTER_ADVANCED=n 372 help 373 This option enables support for a netlink-based userspace interface 374 375config NF_CT_NETLINK_TIMEOUT 376 tristate 'Connection tracking timeout tuning via Netlink' 377 select NETFILTER_NETLINK 378 depends on NETFILTER_ADVANCED 379 depends on NF_CONNTRACK_TIMEOUT 380 help 381 This option enables support for connection tracking timeout 382 fine-grain tuning. This allows you to attach specific timeout 383 policies to flows, instead of using the global timeout policy. 384 385 If unsure, say `N'. 386 387config NF_CT_NETLINK_HELPER 388 tristate 'Connection tracking helpers in user-space via Netlink' 389 select NETFILTER_NETLINK 390 depends on NF_CT_NETLINK 391 depends on NETFILTER_NETLINK_QUEUE 392 depends on NETFILTER_NETLINK_GLUE_CT 393 depends on NETFILTER_ADVANCED 394 help 395 This option enables the user-space connection tracking helpers 396 infrastructure. 397 398 If unsure, say `N'. 399 400config NETFILTER_NETLINK_GLUE_CT 401 bool "NFQUEUE and NFLOG integration with Connection Tracking" 402 default n 403 depends on (NETFILTER_NETLINK_QUEUE || NETFILTER_NETLINK_LOG) && NF_CT_NETLINK 404 help 405 If this option is enabled, NFQUEUE and NFLOG can include 406 Connection Tracking information together with the packet is 407 the enqueued via NFNETLINK. 408 409config NF_NAT 410 tristate "Network Address Translation support" 411 depends on NF_CONNTRACK 412 default m if NETFILTER_ADVANCED=n 413 help 414 The NAT option allows masquerading, port forwarding and other 415 forms of full Network Address Port Translation. This can be 416 controlled by iptables, ip6tables or nft. 417 418config NF_NAT_AMANDA 419 tristate 420 depends on NF_CONNTRACK && NF_NAT 421 default NF_NAT && NF_CONNTRACK_AMANDA 422 423config NF_NAT_FTP 424 tristate 425 depends on NF_CONNTRACK && NF_NAT 426 default NF_NAT && NF_CONNTRACK_FTP 427 428config NF_NAT_IRC 429 tristate 430 depends on NF_CONNTRACK && NF_NAT 431 default NF_NAT && NF_CONNTRACK_IRC 432 433config NF_NAT_SIP 434 tristate 435 depends on NF_CONNTRACK && NF_NAT 436 default NF_NAT && NF_CONNTRACK_SIP 437 438config NF_NAT_TFTP 439 tristate 440 depends on NF_CONNTRACK && NF_NAT 441 default NF_NAT && NF_CONNTRACK_TFTP 442 443config NF_NAT_REDIRECT 444 bool 445 446config NF_NAT_MASQUERADE 447 bool 448 449config NETFILTER_SYNPROXY 450 tristate 451 452endif # NF_CONNTRACK 453 454config NF_TABLES 455 select NETFILTER_NETLINK 456 select LIBCRC32C 457 tristate "Netfilter nf_tables support" 458 help 459 nftables is the new packet classification framework that intends to 460 replace the existing {ip,ip6,arp,eb}_tables infrastructure. It 461 provides a pseudo-state machine with an extensible instruction-set 462 (also known as expressions) that the userspace 'nft' utility 463 (https://www.netfilter.org/projects/nftables) uses to build the 464 rule-set. It also comes with the generic set infrastructure that 465 allows you to construct mappings between matchings and actions 466 for performance lookups. 467 468 To compile it as a module, choose M here. 469 470if NF_TABLES 471config NF_TABLES_INET 472 depends on IPV6 473 select NF_TABLES_IPV4 474 select NF_TABLES_IPV6 475 bool "Netfilter nf_tables mixed IPv4/IPv6 tables support" 476 help 477 This option enables support for a mixed IPv4/IPv6 "inet" table. 478 479config NF_TABLES_NETDEV 480 bool "Netfilter nf_tables netdev tables support" 481 help 482 This option enables support for the "netdev" table. 483 484config NFT_NUMGEN 485 tristate "Netfilter nf_tables number generator module" 486 help 487 This option adds the number generator expression used to perform 488 incremental counting and random numbers bound to a upper limit. 489 490config NFT_CT 491 depends on NF_CONNTRACK 492 tristate "Netfilter nf_tables conntrack module" 493 help 494 This option adds the "ct" expression that you can use to match 495 connection tracking information such as the flow state. 496 497config NFT_FLOW_OFFLOAD 498 depends on NF_CONNTRACK && NF_FLOW_TABLE 499 tristate "Netfilter nf_tables hardware flow offload module" 500 help 501 This option adds the "flow_offload" expression that you can use to 502 choose what flows are placed into the hardware. 503 504config NFT_COUNTER 505 tristate "Netfilter nf_tables counter module" 506 help 507 This option adds the "counter" expression that you can use to 508 include packet and byte counters in a rule. 509 510config NFT_CONNLIMIT 511 tristate "Netfilter nf_tables connlimit module" 512 depends on NF_CONNTRACK 513 depends on NETFILTER_ADVANCED 514 select NETFILTER_CONNCOUNT 515 help 516 This option adds the "connlimit" expression that you can use to 517 ratelimit rule matchings per connections. 518 519config NFT_LOG 520 tristate "Netfilter nf_tables log module" 521 help 522 This option adds the "log" expression that you can use to log 523 packets matching some criteria. 524 525config NFT_LIMIT 526 tristate "Netfilter nf_tables limit module" 527 help 528 This option adds the "limit" expression that you can use to 529 ratelimit rule matchings. 530 531config NFT_MASQ 532 depends on NF_CONNTRACK 533 depends on NF_NAT 534 select NF_NAT_MASQUERADE 535 tristate "Netfilter nf_tables masquerade support" 536 help 537 This option adds the "masquerade" expression that you can use 538 to perform NAT in the masquerade flavour. 539 540config NFT_REDIR 541 depends on NF_CONNTRACK 542 depends on NF_NAT 543 tristate "Netfilter nf_tables redirect support" 544 select NF_NAT_REDIRECT 545 help 546 This options adds the "redirect" expression that you can use 547 to perform NAT in the redirect flavour. 548 549config NFT_NAT 550 depends on NF_CONNTRACK 551 select NF_NAT 552 depends on NF_TABLES_IPV4 || NF_TABLES_IPV6 553 tristate "Netfilter nf_tables nat module" 554 help 555 This option adds the "nat" expression that you can use to perform 556 typical Network Address Translation (NAT) packet transformations. 557 558config NFT_TUNNEL 559 tristate "Netfilter nf_tables tunnel module" 560 help 561 This option adds the "tunnel" expression that you can use to set 562 tunneling policies. 563 564config NFT_OBJREF 565 tristate "Netfilter nf_tables stateful object reference module" 566 help 567 This option adds the "objref" expression that allows you to refer to 568 stateful objects, such as counters and quotas. 569 570config NFT_QUEUE 571 depends on NETFILTER_NETLINK_QUEUE 572 tristate "Netfilter nf_tables queue module" 573 help 574 This is required if you intend to use the userspace queueing 575 infrastructure (also known as NFQUEUE) from nftables. 576 577config NFT_QUOTA 578 tristate "Netfilter nf_tables quota module" 579 help 580 This option adds the "quota" expression that you can use to match 581 enforce bytes quotas. 582 583config NFT_REJECT 584 default m if NETFILTER_ADVANCED=n 585 tristate "Netfilter nf_tables reject support" 586 depends on !NF_TABLES_INET || (IPV6!=m || m) 587 help 588 This option adds the "reject" expression that you can use to 589 explicitly deny and notify via TCP reset/ICMP informational errors 590 unallowed traffic. 591 592config NFT_REJECT_INET 593 depends on NF_TABLES_INET 594 default NFT_REJECT 595 tristate 596 597config NFT_COMPAT 598 depends on NETFILTER_XTABLES 599 tristate "Netfilter x_tables over nf_tables module" 600 help 601 This is required if you intend to use any of existing 602 x_tables match/target extensions over the nf_tables 603 framework. 604 605config NFT_HASH 606 tristate "Netfilter nf_tables hash module" 607 help 608 This option adds the "hash" expression that you can use to perform 609 a hash operation on registers. 610 611config NFT_FIB 612 tristate 613 614config NFT_FIB_INET 615 depends on NF_TABLES_INET 616 depends on NFT_FIB_IPV4 617 depends on NFT_FIB_IPV6 618 tristate "Netfilter nf_tables fib inet support" 619 help 620 This option allows using the FIB expression from the inet table. 621 The lookup will be delegated to the IPv4 or IPv6 FIB depending 622 on the protocol of the packet. 623 624config NFT_XFRM 625 tristate "Netfilter nf_tables xfrm/IPSec security association matching" 626 depends on XFRM 627 help 628 This option adds an expression that you can use to extract properties 629 of a packets security association. 630 631config NFT_SOCKET 632 tristate "Netfilter nf_tables socket match support" 633 depends on IPV6 || IPV6=n 634 select NF_SOCKET_IPV4 635 select NF_SOCKET_IPV6 if NF_TABLES_IPV6 636 help 637 This option allows matching for the presence or absence of a 638 corresponding socket and its attributes. 639 640config NFT_OSF 641 tristate "Netfilter nf_tables passive OS fingerprint support" 642 depends on NETFILTER_ADVANCED 643 select NETFILTER_NETLINK_OSF 644 help 645 This option allows matching packets from an specific OS. 646 647config NFT_TPROXY 648 tristate "Netfilter nf_tables tproxy support" 649 depends on IPV6 || IPV6=n 650 select NF_DEFRAG_IPV4 651 select NF_DEFRAG_IPV6 if NF_TABLES_IPV6 652 select NF_TPROXY_IPV4 653 select NF_TPROXY_IPV6 if NF_TABLES_IPV6 654 help 655 This makes transparent proxy support available in nftables. 656 657config NFT_SYNPROXY 658 tristate "Netfilter nf_tables SYNPROXY expression support" 659 depends on NF_CONNTRACK && NETFILTER_ADVANCED 660 select NETFILTER_SYNPROXY 661 select SYN_COOKIES 662 help 663 The SYNPROXY expression allows you to intercept TCP connections and 664 establish them using syncookies before they are passed on to the 665 server. This allows to avoid conntrack and server resource usage 666 during SYN-flood attacks. 667 668if NF_TABLES_NETDEV 669 670config NF_DUP_NETDEV 671 tristate "Netfilter packet duplication support" 672 help 673 This option enables the generic packet duplication infrastructure 674 for Netfilter. 675 676config NFT_DUP_NETDEV 677 tristate "Netfilter nf_tables netdev packet duplication support" 678 select NF_DUP_NETDEV 679 help 680 This option enables packet duplication for the "netdev" family. 681 682config NFT_FWD_NETDEV 683 tristate "Netfilter nf_tables netdev packet forwarding support" 684 select NF_DUP_NETDEV 685 help 686 This option enables packet forwarding for the "netdev" family. 687 688config NFT_FIB_NETDEV 689 depends on NFT_FIB_IPV4 690 depends on NFT_FIB_IPV6 691 tristate "Netfilter nf_tables netdev fib lookups support" 692 help 693 This option allows using the FIB expression from the netdev table. 694 The lookup will be delegated to the IPv4 or IPv6 FIB depending 695 on the protocol of the packet. 696 697config NFT_REJECT_NETDEV 698 depends on NFT_REJECT_IPV4 699 depends on NFT_REJECT_IPV6 700 tristate "Netfilter nf_tables netdev REJECT support" 701 help 702 This option enables the REJECT support from the netdev table. 703 The return packet generation will be delegated to the IPv4 704 or IPv6 ICMP or TCP RST implementation depending on the 705 protocol of the packet. 706 707endif # NF_TABLES_NETDEV 708 709endif # NF_TABLES 710 711config NF_FLOW_TABLE_INET 712 tristate "Netfilter flow table mixed IPv4/IPv6 module" 713 depends on NF_FLOW_TABLE 714 help 715 This option adds the flow table mixed IPv4/IPv6 support. 716 717 To compile it as a module, choose M here. 718 719config NF_FLOW_TABLE 720 tristate "Netfilter flow table module" 721 depends on NETFILTER_INGRESS 722 depends on NF_CONNTRACK 723 depends on NF_TABLES 724 help 725 This option adds the flow table core infrastructure. 726 727 To compile it as a module, choose M here. 728 729config NETFILTER_XTABLES 730 tristate "Netfilter Xtables support (required for ip_tables)" 731 default m if NETFILTER_ADVANCED=n 732 help 733 This is required if you intend to use any of ip_tables, 734 ip6_tables or arp_tables. 735 736if NETFILTER_XTABLES 737 738comment "Xtables combined modules" 739 740config NETFILTER_XT_MARK 741 tristate 'nfmark target and match support' 742 default m if NETFILTER_ADVANCED=n 743 help 744 This option adds the "MARK" target and "mark" match. 745 746 Netfilter mark matching allows you to match packets based on the 747 "nfmark" value in the packet. 748 The target allows you to create rules in the "mangle" table which alter 749 the netfilter mark (nfmark) field associated with the packet. 750 751 Prior to routing, the nfmark can influence the routing method and can 752 also be used by other subsystems to change their behavior. 753 754config NETFILTER_XT_CONNMARK 755 tristate 'ctmark target and match support' 756 depends on NF_CONNTRACK 757 depends on NETFILTER_ADVANCED 758 select NF_CONNTRACK_MARK 759 help 760 This option adds the "CONNMARK" target and "connmark" match. 761 762 Netfilter allows you to store a mark value per connection (a.k.a. 763 ctmark), similarly to the packet mark (nfmark). Using this 764 target and match, you can set and match on this mark. 765 766config NETFILTER_XT_SET 767 tristate 'set target and match support' 768 depends on IP_SET 769 depends on NETFILTER_ADVANCED 770 help 771 This option adds the "SET" target and "set" match. 772 773 Using this target and match, you can add/delete and match 774 elements in the sets created by ipset(8). 775 776 To compile it as a module, choose M here. If unsure, say N. 777 778# alphabetically ordered list of targets 779 780comment "Xtables targets" 781 782config NETFILTER_XT_TARGET_AUDIT 783 tristate "AUDIT target support" 784 depends on AUDIT 785 depends on NETFILTER_ADVANCED 786 help 787 This option adds a 'AUDIT' target, which can be used to create 788 audit records for packets dropped/accepted. 789 790 To compileit as a module, choose M here. If unsure, say N. 791 792config NETFILTER_XT_TARGET_CHECKSUM 793 tristate "CHECKSUM target support" 794 depends on IP_NF_MANGLE || IP6_NF_MANGLE 795 depends on NETFILTER_ADVANCED 796 help 797 This option adds a `CHECKSUM' target, which can be used in the iptables mangle 798 table to work around buggy DHCP clients in virtualized environments. 799 800 Some old DHCP clients drop packets because they are not aware 801 that the checksum would normally be offloaded to hardware and 802 thus should be considered valid. 803 This target can be used to fill in the checksum using iptables 804 when such packets are sent via a virtual network device. 805 806 To compile it as a module, choose M here. If unsure, say N. 807 808config NETFILTER_XT_TARGET_CLASSIFY 809 tristate '"CLASSIFY" target support' 810 depends on NETFILTER_ADVANCED 811 help 812 This option adds a `CLASSIFY' target, which enables the user to set 813 the priority of a packet. Some qdiscs can use this value for 814 classification, among these are: 815 816 atm, cbq, dsmark, pfifo_fast, htb, prio 817 818 To compile it as a module, choose M here. If unsure, say N. 819 820config NETFILTER_XT_TARGET_CONNMARK 821 tristate '"CONNMARK" target support' 822 depends on NF_CONNTRACK 823 depends on NETFILTER_ADVANCED 824 select NETFILTER_XT_CONNMARK 825 help 826 This is a backwards-compat option for the user's convenience 827 (e.g. when running oldconfig). It selects 828 CONFIG_NETFILTER_XT_CONNMARK (combined connmark/CONNMARK module). 829 830config NETFILTER_XT_TARGET_CONNSECMARK 831 tristate '"CONNSECMARK" target support' 832 depends on NF_CONNTRACK && NF_CONNTRACK_SECMARK 833 default m if NETFILTER_ADVANCED=n 834 help 835 The CONNSECMARK target copies security markings from packets 836 to connections, and restores security markings from connections 837 to packets (if the packets are not already marked). This would 838 normally be used in conjunction with the SECMARK target. 839 840 To compile it as a module, choose M here. If unsure, say N. 841 842config NETFILTER_XT_TARGET_CT 843 tristate '"CT" target support' 844 depends on NF_CONNTRACK 845 depends on IP_NF_RAW || IP6_NF_RAW 846 depends on NETFILTER_ADVANCED 847 help 848 This options adds a `CT' target, which allows to specify initial 849 connection tracking parameters like events to be delivered and 850 the helper to be used. 851 852 To compile it as a module, choose M here. If unsure, say N. 853 854config NETFILTER_XT_TARGET_DSCP 855 tristate '"DSCP" and "TOS" target support' 856 depends on IP_NF_MANGLE || IP6_NF_MANGLE 857 depends on NETFILTER_ADVANCED 858 help 859 This option adds a `DSCP' target, which allows you to manipulate 860 the IPv4/IPv6 header DSCP field (differentiated services codepoint). 861 862 The DSCP field can have any value between 0x0 and 0x3f inclusive. 863 864 It also adds the "TOS" target, which allows you to create rules in 865 the "mangle" table which alter the Type Of Service field of an IPv4 866 or the Priority field of an IPv6 packet, prior to routing. 867 868 To compile it as a module, choose M here. If unsure, say N. 869 870config NETFILTER_XT_TARGET_HL 871 tristate '"HL" hoplimit target support' 872 depends on IP_NF_MANGLE || IP6_NF_MANGLE 873 depends on NETFILTER_ADVANCED 874 help 875 This option adds the "HL" (for IPv6) and "TTL" (for IPv4) 876 targets, which enable the user to change the 877 hoplimit/time-to-live value of the IP header. 878 879 While it is safe to decrement the hoplimit/TTL value, the 880 modules also allow to increment and set the hoplimit value of 881 the header to arbitrary values. This is EXTREMELY DANGEROUS 882 since you can easily create immortal packets that loop 883 forever on the network. 884 885config NETFILTER_XT_TARGET_HMARK 886 tristate '"HMARK" target support' 887 depends on IP6_NF_IPTABLES || IP6_NF_IPTABLES=n 888 depends on NETFILTER_ADVANCED 889 help 890 This option adds the "HMARK" target. 891 892 The target allows you to create rules in the "raw" and "mangle" tables 893 which set the skbuff mark by means of hash calculation within a given 894 range. The nfmark can influence the routing method and can also be used 895 by other subsystems to change their behaviour. 896 897 To compile it as a module, choose M here. If unsure, say N. 898 899config NETFILTER_XT_TARGET_IDLETIMER 900 tristate "IDLETIMER target support" 901 depends on NETFILTER_ADVANCED 902 help 903 904 This option adds the `IDLETIMER' target. Each matching packet 905 resets the timer associated with label specified when the rule is 906 added. When the timer expires, it triggers a sysfs notification. 907 The remaining time for expiration can be read via sysfs. 908 909 To compile it as a module, choose M here. If unsure, say N. 910 911config NETFILTER_XT_TARGET_LED 912 tristate '"LED" target support' 913 depends on LEDS_CLASS && LEDS_TRIGGERS 914 depends on NETFILTER_ADVANCED 915 help 916 This option adds a `LED' target, which allows you to blink LEDs in 917 response to particular packets passing through your machine. 918 919 This can be used to turn a spare LED into a network activity LED, 920 which only flashes in response to FTP transfers, for example. Or 921 you could have an LED which lights up for a minute or two every time 922 somebody connects to your machine via SSH. 923 924 You will need support for the "led" class to make this work. 925 926 To create an LED trigger for incoming SSH traffic: 927 iptables -A INPUT -p tcp --dport 22 -j LED --led-trigger-id ssh --led-delay 1000 928 929 Then attach the new trigger to an LED on your system: 930 echo netfilter-ssh > /sys/class/leds/<ledname>/trigger 931 932 For more information on the LEDs available on your system, see 933 Documentation/leds/leds-class.rst 934 935config NETFILTER_XT_TARGET_LOG 936 tristate "LOG target support" 937 select NF_LOG_COMMON 938 select NF_LOG_SYSLOG 939 select NF_LOG_IPV6 if IP6_NF_IPTABLES 940 default m if NETFILTER_ADVANCED=n 941 help 942 This option adds a `LOG' target, which allows you to create rules in 943 any iptables table which records the packet header to the syslog. 944 945 To compile it as a module, choose M here. If unsure, say N. 946 947config NETFILTER_XT_TARGET_MARK 948 tristate '"MARK" target support' 949 depends on NETFILTER_ADVANCED 950 select NETFILTER_XT_MARK 951 help 952 This is a backwards-compat option for the user's convenience 953 (e.g. when running oldconfig). It selects 954 CONFIG_NETFILTER_XT_MARK (combined mark/MARK module). 955 956config NETFILTER_XT_NAT 957 tristate '"SNAT and DNAT" targets support' 958 depends on NF_NAT 959 help 960 This option enables the SNAT and DNAT targets. 961 962 To compile it as a module, choose M here. If unsure, say N. 963 964config NETFILTER_XT_TARGET_NETMAP 965 tristate '"NETMAP" target support' 966 depends on NF_NAT 967 help 968 NETMAP is an implementation of static 1:1 NAT mapping of network 969 addresses. It maps the network address part, while keeping the host 970 address part intact. 971 972 To compile it as a module, choose M here. If unsure, say N. 973 974config NETFILTER_XT_TARGET_NFLOG 975 tristate '"NFLOG" target support' 976 default m if NETFILTER_ADVANCED=n 977 select NETFILTER_NETLINK_LOG 978 help 979 This option enables the NFLOG target, which allows to LOG 980 messages through nfnetlink_log. 981 982 To compile it as a module, choose M here. If unsure, say N. 983 984config NETFILTER_XT_TARGET_NFQUEUE 985 tristate '"NFQUEUE" target Support' 986 depends on NETFILTER_ADVANCED 987 select NETFILTER_NETLINK_QUEUE 988 help 989 This target replaced the old obsolete QUEUE target. 990 991 As opposed to QUEUE, it supports 65535 different queues, 992 not just one. 993 994 To compile it as a module, choose M here. If unsure, say N. 995 996config NETFILTER_XT_TARGET_NOTRACK 997 tristate '"NOTRACK" target support (DEPRECATED)' 998 depends on NF_CONNTRACK 999 depends on IP_NF_RAW || IP6_NF_RAW 1000 depends on NETFILTER_ADVANCED 1001 select NETFILTER_XT_TARGET_CT 1002 1003config NETFILTER_XT_TARGET_RATEEST 1004 tristate '"RATEEST" target support' 1005 depends on NETFILTER_ADVANCED 1006 help 1007 This option adds a `RATEEST' target, which allows to measure 1008 rates similar to TC estimators. The `rateest' match can be 1009 used to match on the measured rates. 1010 1011 To compile it as a module, choose M here. If unsure, say N. 1012 1013config NETFILTER_XT_TARGET_REDIRECT 1014 tristate "REDIRECT target support" 1015 depends on NF_NAT 1016 select NF_NAT_REDIRECT 1017 help 1018 REDIRECT is a special case of NAT: all incoming connections are 1019 mapped onto the incoming interface's address, causing the packets to 1020 come to the local machine instead of passing through. This is 1021 useful for transparent proxies. 1022 1023 To compile it as a module, choose M here. If unsure, say N. 1024 1025config NETFILTER_XT_TARGET_MASQUERADE 1026 tristate "MASQUERADE target support" 1027 depends on NF_NAT 1028 default m if NETFILTER_ADVANCED=n 1029 select NF_NAT_MASQUERADE 1030 help 1031 Masquerading is a special case of NAT: all outgoing connections are 1032 changed to seem to come from a particular interface's address, and 1033 if the interface goes down, those connections are lost. This is 1034 only useful for dialup accounts with dynamic IP address (ie. your IP 1035 address will be different on next dialup). 1036 1037 To compile it as a module, choose M here. If unsure, say N. 1038 1039config NETFILTER_XT_TARGET_TEE 1040 tristate '"TEE" - packet cloning to alternate destination' 1041 depends on NETFILTER_ADVANCED 1042 depends on IPV6 || IPV6=n 1043 depends on !NF_CONNTRACK || NF_CONNTRACK 1044 depends on IP6_NF_IPTABLES || !IP6_NF_IPTABLES 1045 select NF_DUP_IPV4 1046 select NF_DUP_IPV6 if IP6_NF_IPTABLES 1047 help 1048 This option adds a "TEE" target with which a packet can be cloned and 1049 this clone be rerouted to another nexthop. 1050 1051config NETFILTER_XT_TARGET_TPROXY 1052 tristate '"TPROXY" target transparent proxying support' 1053 depends on NETFILTER_XTABLES 1054 depends on NETFILTER_ADVANCED 1055 depends on IPV6 || IPV6=n 1056 depends on IP6_NF_IPTABLES || IP6_NF_IPTABLES=n 1057 depends on IP_NF_MANGLE 1058 select NF_DEFRAG_IPV4 1059 select NF_DEFRAG_IPV6 if IP6_NF_IPTABLES != n 1060 select NF_TPROXY_IPV4 1061 select NF_TPROXY_IPV6 if IP6_NF_IPTABLES 1062 help 1063 This option adds a `TPROXY' target, which is somewhat similar to 1064 REDIRECT. It can only be used in the mangle table and is useful 1065 to redirect traffic to a transparent proxy. It does _not_ depend 1066 on Netfilter connection tracking and NAT, unlike REDIRECT. 1067 For it to work you will have to configure certain iptables rules 1068 and use policy routing. For more information on how to set it up 1069 see Documentation/networking/tproxy.rst. 1070 1071 To compile it as a module, choose M here. If unsure, say N. 1072 1073config NETFILTER_XT_TARGET_TRACE 1074 tristate '"TRACE" target support' 1075 depends on IP_NF_RAW || IP6_NF_RAW 1076 depends on NETFILTER_ADVANCED 1077 help 1078 The TRACE target allows you to mark packets so that the kernel 1079 will log every rule which match the packets as those traverse 1080 the tables, chains, rules. 1081 1082 If you want to compile it as a module, say M here and read 1083 <file:Documentation/kbuild/modules.rst>. If unsure, say `N'. 1084 1085config NETFILTER_XT_TARGET_SECMARK 1086 tristate '"SECMARK" target support' 1087 depends on NETWORK_SECMARK 1088 default m if NETFILTER_ADVANCED=n 1089 help 1090 The SECMARK target allows security marking of network 1091 packets, for use with security subsystems. 1092 1093 To compile it as a module, choose M here. If unsure, say N. 1094 1095config NETFILTER_XT_TARGET_TCPMSS 1096 tristate '"TCPMSS" target support' 1097 depends on IPV6 || IPV6=n 1098 default m if NETFILTER_ADVANCED=n 1099 help 1100 This option adds a `TCPMSS' target, which allows you to alter the 1101 MSS value of TCP SYN packets, to control the maximum size for that 1102 connection (usually limiting it to your outgoing interface's MTU 1103 minus 40). 1104 1105 This is used to overcome criminally braindead ISPs or servers which 1106 block ICMP Fragmentation Needed packets. The symptoms of this 1107 problem are that everything works fine from your Linux 1108 firewall/router, but machines behind it can never exchange large 1109 packets: 1110 1) Web browsers connect, then hang with no data received. 1111 2) Small mail works fine, but large emails hang. 1112 3) ssh works fine, but scp hangs after initial handshaking. 1113 1114 Workaround: activate this option and add a rule to your firewall 1115 configuration like: 1116 1117 iptables -A FORWARD -p tcp --tcp-flags SYN,RST SYN \ 1118 -j TCPMSS --clamp-mss-to-pmtu 1119 1120 To compile it as a module, choose M here. If unsure, say N. 1121 1122config NETFILTER_XT_TARGET_TCPOPTSTRIP 1123 tristate '"TCPOPTSTRIP" target support' 1124 depends on IP_NF_MANGLE || IP6_NF_MANGLE 1125 depends on NETFILTER_ADVANCED 1126 help 1127 This option adds a "TCPOPTSTRIP" target, which allows you to strip 1128 TCP options from TCP packets. 1129 1130# alphabetically ordered list of matches 1131 1132comment "Xtables matches" 1133 1134config NETFILTER_XT_MATCH_ADDRTYPE 1135 tristate '"addrtype" address type match support' 1136 default m if NETFILTER_ADVANCED=n 1137 help 1138 This option allows you to match what routing thinks of an address, 1139 eg. UNICAST, LOCAL, BROADCAST, ... 1140 1141 If you want to compile it as a module, say M here and read 1142 <file:Documentation/kbuild/modules.rst>. If unsure, say `N'. 1143 1144config NETFILTER_XT_MATCH_BPF 1145 tristate '"bpf" match support' 1146 depends on NETFILTER_ADVANCED 1147 help 1148 BPF matching applies a linux socket filter to each packet and 1149 accepts those for which the filter returns non-zero. 1150 1151 To compile it as a module, choose M here. If unsure, say N. 1152 1153config NETFILTER_XT_MATCH_CGROUP 1154 tristate '"control group" match support' 1155 depends on NETFILTER_ADVANCED 1156 depends on CGROUPS 1157 select CGROUP_NET_CLASSID 1158 help 1159 Socket/process control group matching allows you to match locally 1160 generated packets based on which net_cls control group processes 1161 belong to. 1162 1163config NETFILTER_XT_MATCH_CLUSTER 1164 tristate '"cluster" match support' 1165 depends on NF_CONNTRACK 1166 depends on NETFILTER_ADVANCED 1167 help 1168 This option allows you to build work-load-sharing clusters of 1169 network servers/stateful firewalls without having a dedicated 1170 load-balancing router/server/switch. Basically, this match returns 1171 true when the packet must be handled by this cluster node. Thus, 1172 all nodes see all packets and this match decides which node handles 1173 what packets. The work-load sharing algorithm is based on source 1174 address hashing. 1175 1176 If you say Y or M here, try `iptables -m cluster --help` for 1177 more information. 1178 1179config NETFILTER_XT_MATCH_COMMENT 1180 tristate '"comment" match support' 1181 depends on NETFILTER_ADVANCED 1182 help 1183 This option adds a `comment' dummy-match, which allows you to put 1184 comments in your iptables ruleset. 1185 1186 If you want to compile it as a module, say M here and read 1187 <file:Documentation/kbuild/modules.rst>. If unsure, say `N'. 1188 1189config NETFILTER_XT_MATCH_CONNBYTES 1190 tristate '"connbytes" per-connection counter match support' 1191 depends on NF_CONNTRACK 1192 depends on NETFILTER_ADVANCED 1193 help 1194 This option adds a `connbytes' match, which allows you to match the 1195 number of bytes and/or packets for each direction within a connection. 1196 1197 If you want to compile it as a module, say M here and read 1198 <file:Documentation/kbuild/modules.rst>. If unsure, say `N'. 1199 1200config NETFILTER_XT_MATCH_CONNLABEL 1201 tristate '"connlabel" match support' 1202 select NF_CONNTRACK_LABELS 1203 depends on NF_CONNTRACK 1204 depends on NETFILTER_ADVANCED 1205 help 1206 This match allows you to test and assign userspace-defined labels names 1207 to a connection. The kernel only stores bit values - mapping 1208 names to bits is done by userspace. 1209 1210 Unlike connmark, more than 32 flag bits may be assigned to a 1211 connection simultaneously. 1212 1213config NETFILTER_XT_MATCH_CONNLIMIT 1214 tristate '"connlimit" match support' 1215 depends on NF_CONNTRACK 1216 depends on NETFILTER_ADVANCED 1217 select NETFILTER_CONNCOUNT 1218 help 1219 This match allows you to match against the number of parallel 1220 connections to a server per client IP address (or address block). 1221 1222config NETFILTER_XT_MATCH_CONNMARK 1223 tristate '"connmark" connection mark match support' 1224 depends on NF_CONNTRACK 1225 depends on NETFILTER_ADVANCED 1226 select NETFILTER_XT_CONNMARK 1227 help 1228 This is a backwards-compat option for the user's convenience 1229 (e.g. when running oldconfig). It selects 1230 CONFIG_NETFILTER_XT_CONNMARK (combined connmark/CONNMARK module). 1231 1232config NETFILTER_XT_MATCH_CONNTRACK 1233 tristate '"conntrack" connection tracking match support' 1234 depends on NF_CONNTRACK 1235 default m if NETFILTER_ADVANCED=n 1236 help 1237 This is a general conntrack match module, a superset of the state match. 1238 1239 It allows matching on additional conntrack information, which is 1240 useful in complex configurations, such as NAT gateways with multiple 1241 internet links or tunnels. 1242 1243 To compile it as a module, choose M here. If unsure, say N. 1244 1245config NETFILTER_XT_MATCH_CPU 1246 tristate '"cpu" match support' 1247 depends on NETFILTER_ADVANCED 1248 help 1249 CPU matching allows you to match packets based on the CPU 1250 currently handling the packet. 1251 1252 To compile it as a module, choose M here. If unsure, say N. 1253 1254config NETFILTER_XT_MATCH_DCCP 1255 tristate '"dccp" protocol match support' 1256 depends on NETFILTER_ADVANCED 1257 default IP_DCCP 1258 help 1259 With this option enabled, you will be able to use the iptables 1260 `dccp' match in order to match on DCCP source/destination ports 1261 and DCCP flags. 1262 1263 If you want to compile it as a module, say M here and read 1264 <file:Documentation/kbuild/modules.rst>. If unsure, say `N'. 1265 1266config NETFILTER_XT_MATCH_DEVGROUP 1267 tristate '"devgroup" match support' 1268 depends on NETFILTER_ADVANCED 1269 help 1270 This options adds a `devgroup' match, which allows to match on the 1271 device group a network device is assigned to. 1272 1273 To compile it as a module, choose M here. If unsure, say N. 1274 1275config NETFILTER_XT_MATCH_DSCP 1276 tristate '"dscp" and "tos" match support' 1277 depends on NETFILTER_ADVANCED 1278 help 1279 This option adds a `DSCP' match, which allows you to match against 1280 the IPv4/IPv6 header DSCP field (differentiated services codepoint). 1281 1282 The DSCP field can have any value between 0x0 and 0x3f inclusive. 1283 1284 It will also add a "tos" match, which allows you to match packets 1285 based on the Type Of Service fields of the IPv4 packet (which share 1286 the same bits as DSCP). 1287 1288 To compile it as a module, choose M here. If unsure, say N. 1289 1290config NETFILTER_XT_MATCH_ECN 1291 tristate '"ecn" match support' 1292 depends on NETFILTER_ADVANCED 1293 help 1294 This option adds an "ECN" match, which allows you to match against 1295 the IPv4 and TCP header ECN fields. 1296 1297 To compile it as a module, choose M here. If unsure, say N. 1298 1299config NETFILTER_XT_MATCH_ESP 1300 tristate '"esp" match support' 1301 depends on NETFILTER_ADVANCED 1302 help 1303 This match extension allows you to match a range of SPIs 1304 inside ESP header of IPSec packets. 1305 1306 To compile it as a module, choose M here. If unsure, say N. 1307 1308config NETFILTER_XT_MATCH_HASHLIMIT 1309 tristate '"hashlimit" match support' 1310 depends on IP6_NF_IPTABLES || IP6_NF_IPTABLES=n 1311 depends on NETFILTER_ADVANCED 1312 help 1313 This option adds a `hashlimit' match. 1314 1315 As opposed to `limit', this match dynamically creates a hash table 1316 of limit buckets, based on your selection of source/destination 1317 addresses and/or ports. 1318 1319 It enables you to express policies like `10kpps for any given 1320 destination address' or `500pps from any given source address' 1321 with a single rule. 1322 1323config NETFILTER_XT_MATCH_HELPER 1324 tristate '"helper" match support' 1325 depends on NF_CONNTRACK 1326 depends on NETFILTER_ADVANCED 1327 help 1328 Helper matching allows you to match packets in dynamic connections 1329 tracked by a conntrack-helper, ie. nf_conntrack_ftp 1330 1331 To compile it as a module, choose M here. If unsure, say Y. 1332 1333config NETFILTER_XT_MATCH_HL 1334 tristate '"hl" hoplimit/TTL match support' 1335 depends on NETFILTER_ADVANCED 1336 help 1337 HL matching allows you to match packets based on the hoplimit 1338 in the IPv6 header, or the time-to-live field in the IPv4 1339 header of the packet. 1340 1341config NETFILTER_XT_MATCH_IPCOMP 1342 tristate '"ipcomp" match support' 1343 depends on NETFILTER_ADVANCED 1344 help 1345 This match extension allows you to match a range of CPIs(16 bits) 1346 inside IPComp header of IPSec packets. 1347 1348 To compile it as a module, choose M here. If unsure, say N. 1349 1350config NETFILTER_XT_MATCH_IPRANGE 1351 tristate '"iprange" address range match support' 1352 depends on NETFILTER_ADVANCED 1353 help 1354 This option adds a "iprange" match, which allows you to match based on 1355 an IP address range. (Normal iptables only matches on single addresses 1356 with an optional mask.) 1357 1358 If unsure, say M. 1359 1360config NETFILTER_XT_MATCH_IPVS 1361 tristate '"ipvs" match support' 1362 depends on IP_VS 1363 depends on NETFILTER_ADVANCED 1364 depends on NF_CONNTRACK 1365 help 1366 This option allows you to match against IPVS properties of a packet. 1367 1368 If unsure, say N. 1369 1370config NETFILTER_XT_MATCH_L2TP 1371 tristate '"l2tp" match support' 1372 depends on NETFILTER_ADVANCED 1373 default L2TP 1374 help 1375 This option adds an "L2TP" match, which allows you to match against 1376 L2TP protocol header fields. 1377 1378 To compile it as a module, choose M here. If unsure, say N. 1379 1380config NETFILTER_XT_MATCH_LENGTH 1381 tristate '"length" match support' 1382 depends on NETFILTER_ADVANCED 1383 help 1384 This option allows you to match the length of a packet against a 1385 specific value or range of values. 1386 1387 To compile it as a module, choose M here. If unsure, say N. 1388 1389config NETFILTER_XT_MATCH_LIMIT 1390 tristate '"limit" match support' 1391 depends on NETFILTER_ADVANCED 1392 help 1393 limit matching allows you to control the rate at which a rule can be 1394 matched: mainly useful in combination with the LOG target ("LOG 1395 target support", below) and to avoid some Denial of Service attacks. 1396 1397 To compile it as a module, choose M here. If unsure, say N. 1398 1399config NETFILTER_XT_MATCH_MAC 1400 tristate '"mac" address match support' 1401 depends on NETFILTER_ADVANCED 1402 help 1403 MAC matching allows you to match packets based on the source 1404 Ethernet address of the packet. 1405 1406 To compile it as a module, choose M here. If unsure, say N. 1407 1408config NETFILTER_XT_MATCH_MARK 1409 tristate '"mark" match support' 1410 depends on NETFILTER_ADVANCED 1411 select NETFILTER_XT_MARK 1412 help 1413 This is a backwards-compat option for the user's convenience 1414 (e.g. when running oldconfig). It selects 1415 CONFIG_NETFILTER_XT_MARK (combined mark/MARK module). 1416 1417config NETFILTER_XT_MATCH_MULTIPORT 1418 tristate '"multiport" Multiple port match support' 1419 depends on NETFILTER_ADVANCED 1420 help 1421 Multiport matching allows you to match TCP or UDP packets based on 1422 a series of source or destination ports: normally a rule can only 1423 match a single range of ports. 1424 1425 To compile it as a module, choose M here. If unsure, say N. 1426 1427config NETFILTER_XT_MATCH_NFACCT 1428 tristate '"nfacct" match support' 1429 depends on NETFILTER_ADVANCED 1430 select NETFILTER_NETLINK_ACCT 1431 help 1432 This option allows you to use the extended accounting through 1433 nfnetlink_acct. 1434 1435 To compile it as a module, choose M here. If unsure, say N. 1436 1437config NETFILTER_XT_MATCH_OSF 1438 tristate '"osf" Passive OS fingerprint match' 1439 depends on NETFILTER_ADVANCED 1440 select NETFILTER_NETLINK_OSF 1441 help 1442 This option selects the Passive OS Fingerprinting match module 1443 that allows to passively match the remote operating system by 1444 analyzing incoming TCP SYN packets. 1445 1446 Rules and loading software can be downloaded from 1447 http://www.ioremap.net/projects/osf 1448 1449 To compile it as a module, choose M here. If unsure, say N. 1450 1451config NETFILTER_XT_MATCH_OWNER 1452 tristate '"owner" match support' 1453 depends on NETFILTER_ADVANCED 1454 help 1455 Socket owner matching allows you to match locally-generated packets 1456 based on who created the socket: the user or group. It is also 1457 possible to check whether a socket actually exists. 1458 1459config NETFILTER_XT_MATCH_POLICY 1460 tristate 'IPsec "policy" match support' 1461 depends on XFRM 1462 default m if NETFILTER_ADVANCED=n 1463 help 1464 Policy matching allows you to match packets based on the 1465 IPsec policy that was used during decapsulation/will 1466 be used during encapsulation. 1467 1468 To compile it as a module, choose M here. If unsure, say N. 1469 1470config NETFILTER_XT_MATCH_PHYSDEV 1471 tristate '"physdev" match support' 1472 depends on BRIDGE && BRIDGE_NETFILTER 1473 depends on NETFILTER_ADVANCED 1474 help 1475 Physdev packet matching matches against the physical bridge ports 1476 the IP packet arrived on or will leave by. 1477 1478 To compile it as a module, choose M here. If unsure, say N. 1479 1480config NETFILTER_XT_MATCH_PKTTYPE 1481 tristate '"pkttype" packet type match support' 1482 depends on NETFILTER_ADVANCED 1483 help 1484 Packet type matching allows you to match a packet by 1485 its "class", eg. BROADCAST, MULTICAST, ... 1486 1487 Typical usage: 1488 iptables -A INPUT -m pkttype --pkt-type broadcast -j LOG 1489 1490 To compile it as a module, choose M here. If unsure, say N. 1491 1492config NETFILTER_XT_MATCH_QUOTA 1493 tristate '"quota" match support' 1494 depends on NETFILTER_ADVANCED 1495 help 1496 This option adds a `quota' match, which allows to match on a 1497 byte counter. 1498 1499 If you want to compile it as a module, say M here and read 1500 <file:Documentation/kbuild/modules.rst>. If unsure, say `N'. 1501 1502config NETFILTER_XT_MATCH_RATEEST 1503 tristate '"rateest" match support' 1504 depends on NETFILTER_ADVANCED 1505 select NETFILTER_XT_TARGET_RATEEST 1506 help 1507 This option adds a `rateest' match, which allows to match on the 1508 rate estimated by the RATEEST target. 1509 1510 To compile it as a module, choose M here. If unsure, say N. 1511 1512config NETFILTER_XT_MATCH_REALM 1513 tristate '"realm" match support' 1514 depends on NETFILTER_ADVANCED 1515 select IP_ROUTE_CLASSID 1516 help 1517 This option adds a `realm' match, which allows you to use the realm 1518 key from the routing subsystem inside iptables. 1519 1520 This match pretty much resembles the CONFIG_NET_CLS_ROUTE4 option 1521 in tc world. 1522 1523 If you want to compile it as a module, say M here and read 1524 <file:Documentation/kbuild/modules.rst>. If unsure, say `N'. 1525 1526config NETFILTER_XT_MATCH_RECENT 1527 tristate '"recent" match support' 1528 depends on NETFILTER_ADVANCED 1529 help 1530 This match is used for creating one or many lists of recently 1531 used addresses and then matching against that/those list(s). 1532 1533 Short options are available by using 'iptables -m recent -h' 1534 Official Website: <http://snowman.net/projects/ipt_recent/> 1535 1536config NETFILTER_XT_MATCH_SCTP 1537 tristate '"sctp" protocol match support' 1538 depends on NETFILTER_ADVANCED 1539 default IP_SCTP 1540 help 1541 With this option enabled, you will be able to use the 1542 `sctp' match in order to match on SCTP source/destination ports 1543 and SCTP chunk types. 1544 1545 If you want to compile it as a module, say M here and read 1546 <file:Documentation/kbuild/modules.rst>. If unsure, say `N'. 1547 1548config NETFILTER_XT_MATCH_SOCKET 1549 tristate '"socket" match support' 1550 depends on NETFILTER_XTABLES 1551 depends on NETFILTER_ADVANCED 1552 depends on IPV6 || IPV6=n 1553 depends on IP6_NF_IPTABLES || IP6_NF_IPTABLES=n 1554 select NF_SOCKET_IPV4 1555 select NF_SOCKET_IPV6 if IP6_NF_IPTABLES 1556 select NF_DEFRAG_IPV4 1557 select NF_DEFRAG_IPV6 if IP6_NF_IPTABLES != n 1558 help 1559 This option adds a `socket' match, which can be used to match 1560 packets for which a TCP or UDP socket lookup finds a valid socket. 1561 It can be used in combination with the MARK target and policy 1562 routing to implement full featured non-locally bound sockets. 1563 1564 To compile it as a module, choose M here. If unsure, say N. 1565 1566config NETFILTER_XT_MATCH_STATE 1567 tristate '"state" match support' 1568 depends on NF_CONNTRACK 1569 default m if NETFILTER_ADVANCED=n 1570 help 1571 Connection state matching allows you to match packets based on their 1572 relationship to a tracked connection (ie. previous packets). This 1573 is a powerful tool for packet classification. 1574 1575 To compile it as a module, choose M here. If unsure, say N. 1576 1577config NETFILTER_XT_MATCH_STATISTIC 1578 tristate '"statistic" match support' 1579 depends on NETFILTER_ADVANCED 1580 help 1581 This option adds a `statistic' match, which allows you to match 1582 on packets periodically or randomly with a given percentage. 1583 1584 To compile it as a module, choose M here. If unsure, say N. 1585 1586config NETFILTER_XT_MATCH_STRING 1587 tristate '"string" match support' 1588 depends on NETFILTER_ADVANCED 1589 select TEXTSEARCH 1590 select TEXTSEARCH_KMP 1591 select TEXTSEARCH_BM 1592 select TEXTSEARCH_FSM 1593 help 1594 This option adds a `string' match, which allows you to look for 1595 pattern matchings in packets. 1596 1597 To compile it as a module, choose M here. If unsure, say N. 1598 1599config NETFILTER_XT_MATCH_TCPMSS 1600 tristate '"tcpmss" match support' 1601 depends on NETFILTER_ADVANCED 1602 help 1603 This option adds a `tcpmss' match, which allows you to examine the 1604 MSS value of TCP SYN packets, which control the maximum packet size 1605 for that connection. 1606 1607 To compile it as a module, choose M here. If unsure, say N. 1608 1609config NETFILTER_XT_MATCH_TIME 1610 tristate '"time" match support' 1611 depends on NETFILTER_ADVANCED 1612 help 1613 This option adds a "time" match, which allows you to match based on 1614 the packet arrival time (at the machine which netfilter is running) 1615 on) or departure time/date (for locally generated packets). 1616 1617 If you say Y here, try `iptables -m time --help` for 1618 more information. 1619 1620 If you want to compile it as a module, say M here. 1621 If unsure, say N. 1622 1623config NETFILTER_XT_MATCH_U32 1624 tristate '"u32" match support' 1625 depends on NETFILTER_ADVANCED 1626 help 1627 u32 allows you to extract quantities of up to 4 bytes from a packet, 1628 AND them with specified masks, shift them by specified amounts and 1629 test whether the results are in any of a set of specified ranges. 1630 The specification of what to extract is general enough to skip over 1631 headers with lengths stored in the packet, as in IP or TCP header 1632 lengths. 1633 1634 Details and examples are in the kernel module source. 1635 1636endif # NETFILTER_XTABLES 1637 1638endmenu 1639 1640source "net/netfilter/ipset/Kconfig" 1641 1642source "net/netfilter/ipvs/Kconfig" 1643