iptables match based on source security context?

Christoph A. casmls at gmail.com
Fri Apr 15 16:16:58 UTC 2011


I'd like to redirect traffic (for transparent proxying) coming from a
program running in a sandbox_net_t (or sandbox_web_t) sandbox, but as
far as I've seen there is no possibility to match/mark packets based on
there local security context origin.

Is that idea somehow possible?

Christoph A.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 163 bytes
Desc: OpenPGP digital signature
Url : http://lists.fedoraproject.org/pipermail/selinux/attachments/20110415/44cd6c7e/attachment.bin 

More information about the selinux mailing list