diff options
author | Joe Stringer <joestringer@nicira.com> | 2015-09-18 13:58:00 -0700 |
---|---|---|
committer | Joe Stringer <joestringer@nicira.com> | 2015-10-13 15:34:15 -0700 |
commit | 8e53fe8cf7a178cf9702fb1bb916f4645058e5e7 (patch) | |
tree | 1eeee5cf97d09d7ed99f4fdd52aaf2bbbe0500a2 /NEWS | |
parent | 07659514c3c1e8998a4935a998b627d716c559f9 (diff) | |
download | openvswitch-8e53fe8cf7a178cf9702fb1bb916f4645058e5e7.tar.gz |
Add connection tracking mark support.
This patch adds a new 32-bit metadata field to the connection tracking
interface. When a mark is specified as part of the ct action and the
connection is committed, the value is saved with the current connection.
Subsequent ct lookups with the table specified will expose this metadata
as the "ct_mark" field in the flow.
For example, to allow new TCP connections from port 1->2 and only allow
established connections from port 2->1, and to associate a mark with those
connections:
table=0,priority=1,action=drop
table=0,arp,action=normal
table=0,in_port=1,tcp,action=ct(commit,exec(set_field:1->ct_mark)),2
table=0,in_port=2,ct_state=-trk,tcp,action=ct(table=1)
table=1,in_port=2,ct_state=+trk,ct_mark=1,tcp,action=1
Signed-off-by: Joe Stringer <joestringer@nicira.com>
Acked-by: Jarno Rajahalme <jrajahalme@nicira.com>
Acked-by: Ben Pfaff <blp@nicira.com>
Diffstat (limited to 'NEWS')
-rw-r--r-- | NEWS | 4 |
1 files changed, 2 insertions, 2 deletions
@@ -25,8 +25,8 @@ Post-v2.4.0 the next OVS release. - Added --user option to all daemons - Add support for connection tracking through the new "ct" action - and "ct_state"/"ct_zone" match fields. Only available on Linux kernels - with the connection tracking module loaded. + and "ct_state"/"ct_zone"/"ct_mark" match fields. Only available on + Linux kernels with the connection tracking module loaded. v2.4.0 - 20 Aug 2015 |