Lines Matching full:allows

10 	  This allows you to classify packets from ingress using the Netfilter
18 This allows you to classify packets before transmission using the
172 extension. This allows you to attach timeout policies to flow
182 This allows you to store the flow start-time and to obtain
241 machine, then you may want to enable this feature. This allows the
401 fine-grain tuning. This allows you to attach specific timeout
433 The NAT option allows masquerading, port forwarding and other
487 allows you to construct mappings between matchings and actions
630 This option allows using the FIB expression from the inet table.
647 This option allows matching for the presence or absence of a
655 This option allows matching packets from an specific OS.
673 The SYNPROXY expression allows you to intercept TCP connections and
675 server. This allows to avoid conntrack and server resource usage
703 This option allows using the FIB expression from the netdev table.
773 Netfilter mark matching allows you to match packets based on the
775 The target allows you to create rules in the "mangle" table which alter
789 Netfilter allows you to store a mark value per connection (a.k.a.
875 This options adds a `CT' target, which allows to specify initial
886 This option adds a `DSCP' target, which allows you to manipulate
891 It also adds the "TOS" target, which allows you to create rules in
919 The target allows you to create rules in the "raw" and "mangle" tables
943 This option adds a `LED' target, which allows you to blink LEDs in
968 This option adds a `LOG' target, which allows you to create rules in
1005 This option enables the NFLOG target, which allows to LOG
1033 This option adds a `RATEEST' target, which allows to measure
1104 The TRACE target allows you to mark packets so that the kernel
1116 The SECMARK target allows security marking of network
1126 This option adds a `TCPMSS' target, which allows you to alter the
1153 This option adds a "TCPOPTSTRIP" target, which allows you to strip
1164 This option allows you to match what routing thinks of an address,
1185 Socket/process control group matching allows you to match locally
1194 This option allows you to build work-load-sharing clusters of
1209 This option adds a `comment' dummy-match, which allows you to put
1220 This option adds a `connbytes' match, which allows you to match the
1232 This match allows you to test and assign userspace-defined labels names
1245 This match allows you to match against the number of parallel
1265 It allows matching on additional conntrack information, which is
1275 CPU matching allows you to match packets based on the CPU
1296 This options adds a `devgroup' match, which allows to match on the
1305 This option adds a `DSCP' match, which allows you to match against
1310 It will also add a "tos" match, which allows you to match packets
1320 This option adds an "ECN" match, which allows you to match against
1329 This match extension allows you to match a range of SPIs
1354 Helper matching allows you to match packets in dynamic connections
1363 HL matching allows you to match packets based on the hoplimit
1371 This match extension allows you to match a range of CPIs(16 bits)
1380 This option adds a "iprange" match, which allows you to match based on
1392 This option allows you to match against IPVS properties of a packet.
1401 This option adds an "L2TP" match, which allows you to match against
1410 This option allows you to match the length of a packet against a
1419 limit matching allows you to control the rate at which a rule can be
1429 MAC matching allows you to match packets based on the source
1447 Multiport matching allows you to match TCP or UDP packets based on
1458 This option allows you to use the extended accounting through
1469 that allows to passively match the remote operating system by
1481 Socket owner matching allows you to match locally-generated packets
1490 Policy matching allows you to match packets based on the
1510 Packet type matching allows you to match a packet by
1522 This option adds a `quota' match, which allows to match on a
1533 This option adds a `rateest' match, which allows to match on the
1543 This option adds a `realm' match, which allows you to use the realm
1597 Connection state matching allows you to match packets based on their
1607 This option adds a `statistic' match, which allows you to match
1620 This option adds a `string' match, which allows you to look for
1629 This option adds a `tcpmss' match, which allows you to examine the
1639 This option adds a "time" match, which allows you to match based on
1653 u32 allows you to extract quantities of up to 4 bytes from a packet,