From 7408cdaa310fe75a6da3d4de165d84fcde123c62 Mon Sep 17 00:00:00 2001 From: Alin Nastac Date: Mon, 25 Jun 2018 10:22:21 +0200 Subject: netfilter: add bpf match support Add xt_bpf modules to {kmod-ipt,iptables-mod}-filter. Match using Linux Socket Filter. Expects a BPF program in decimal format. This is the format generated by the nfbpf_compile utility. Signed-off-by: Alin Nastac (backported from ab07ae2f27dd920cb7ba186d9f7ad2ccb1c980c4) --- include/netfilter.mk | 1 + 1 file changed, 1 insertion(+) (limited to 'include') diff --git a/include/netfilter.mk b/include/netfilter.mk index 5d532cea5b..510aa183ca 100644 --- a/include/netfilter.mk +++ b/include/netfilter.mk @@ -106,6 +106,7 @@ $(eval $(call nf_add,IPT_PHYSDEV,CONFIG_NETFILTER_XT_MATCH_PHYSDEV, $(P_XT)xt_ph # filter $(eval $(call nf_add,IPT_FILTER,CONFIG_NETFILTER_XT_MATCH_STRING, $(P_XT)xt_string)) +$(eval $(call nf_add,IPT_FILTER,CONFIG_NETFILTER_XT_MATCH_BPF, $(P_XT)xt_bpf)) # ipopt -- cgit v1.2.3