Blame bootstrap_ver/extensions/libxt_connlabel.man

Packit Service dd8e2b
Module matches or adds connlabels to a connection.
Packit Service dd8e2b
connlabels are similar to connmarks, except labels are bit-based; i.e.
Packit Service dd8e2b
all labels may be attached to a flow at the same time.
Packit Service dd8e2b
Up to 128 unique labels are currently supported.
Packit Service dd8e2b
.TP
Packit Service dd8e2b
[\fB!\fP] \fB\-\-label\fP \fBname\fP
Packit Service dd8e2b
matches if label \fBname\fP has been set on a connection.
Packit Service dd8e2b
Instead of a name (which will be translated to a number, see EXAMPLE below),
Packit Service dd8e2b
a number may be used instead.  Using a number always overrides connlabel.conf.
Packit Service dd8e2b
.TP
Packit Service dd8e2b
\fB\-\-set\fP
Packit Service dd8e2b
if the label has not been set on the connection, set it.
Packit Service dd8e2b
Note that setting a label can fail.  This is because the kernel allocates the
Packit Service dd8e2b
conntrack label storage area when the connection is created, and it only
Packit Service dd8e2b
reserves the amount of memory required by the ruleset that exists at
Packit Service dd8e2b
the time the connection is created.
Packit Service dd8e2b
In this case, the match will fail (or succeed, in case \fB\-\-label\fP
Packit Service dd8e2b
option was negated).
Packit Service dd8e2b
.PP
Packit Service dd8e2b
This match depends on libnetfilter_conntrack 1.0.4 or later.
Packit Service dd8e2b
Label translation is done via the \fB/etc/xtables/connlabel.conf\fP configuration file.
Packit Service dd8e2b
.PP
Packit Service dd8e2b
Example:
Packit Service dd8e2b
.IP
Packit Service dd8e2b
.nf
Packit Service dd8e2b
0	eth0-in
Packit Service dd8e2b
1	eth0-out
Packit Service dd8e2b
2	ppp-in
Packit Service dd8e2b
3	ppp-out
Packit Service dd8e2b
4	bulk-traffic
Packit Service dd8e2b
5	interactive
Packit Service dd8e2b
.fi
Packit Service dd8e2b
.PP