| commit | a39bdce2f2a9aebda1b9438c4b2e91c0dd507a34 | [log] [tgz] |
|---|---|---|
| author | Ulrich Weber <ulrich.weber@sophos.com> | Thu Oct 25 05:34:45 2012 +0000 |
| committer | Greg Kroah-Hartman <gregkh@linuxfoundation.org> | Mon Nov 26 11:37:48 2012 -0800 |
| tree | a673b6e766711591f4e54bca916de7e5f799cf71 | |
| parent | b3e991ea9222c3ec71d74b37d105cea115055c4d [diff] |
netfilter: nf_nat: don't check for port change on ICMP tuples commit 38fe36a248ec3228f8e6507955d7ceb0432d2000 upstream. ICMP tuples have id in src and type/code in dst. So comparing src.u.all with dst.u.all will always fail here and ip_xfrm_me_harder() is called for every ICMP packet, even if there was no NAT. Signed-off-by: Ulrich Weber <ulrich.weber@sophos.com> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>