12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

488CHAPTER 24Configuring a FirewallownerFor packets created on this system, match characteristics of the packet creator. Onlyworks in the OUTPUT chain. Some packets don’t match because they don’t have acreator.--uid-owner Matches if the process that created the packet is owned by the given user.--gid-owner Matches if the process that created the packet has the given effective group ID.--pid-owner Matches if the process that created the packet has the given process ID.--sid-owner Matches if the process that created the packet is in the given session group.--cmd-owner Matches if the process that created the packet has the provided command name.physdevMatch based on the bridge port input and output devices.--physdev-in [!] Name of a bridge port from which the packet was received. Only works if thepacket entered in the INPUT, FORWARD, or PREROUTING chain. If the name ends in a+, then any interface beginning with the given name matches.--physdev-out [!] Name of the bridge port from which the packet is sent. Only works if the packetentered in the FORWARD, OUTPUT, or POSTROUTING chain. If the interface name endsin a +, then any interface beginning with this name will match.[!] --physdev-is-inMatches if the packet has entered through a bridge interface.[!] --physdev-is-outMatches if the packet will leave through a bridge interface.[!] --physdev-is-bridgedMatches if the packet is being bridged and not routed. Only works in the FORWARDor POSTROUTING chain.pkttypeMatches based on the link-layer packet type.--pkt-type must be one of unicast, broadcast, or multicast.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!