Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.misc > #70357 > unrolled thread
| Started by | Lawrence D'Oliveiro <ldo@nz.invalid> |
|---|---|
| First post | 2025-08-05 08:14 +0000 |
| Last post | 2025-08-23 05:43 +0000 |
| Articles | 20 on this page of 113 — 24 participants |
Back to article view | Back to comp.os.linux.misc
Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-05 08:14 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-05 11:22 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marco Moock <mm@dorfdsl.de> - 2025-08-05 11:34 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use jayjwa <jayjwa@atr2.ath.cx.invalid> - 2025-08-05 11:30 -0400
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use The Natural Philosopher <tnp@invalid.invalid> - 2025-08-05 19:56 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-06 01:06 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use John McCue <jmclnx@gmail.com.invalid> - 2025-08-06 01:32 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-06 04:20 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use c186282 <c186282@nnada.net> - 2025-08-06 01:33 -0400
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-06 09:31 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-06 08:56 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Nuno Silva <nunojsilva@invalid.invalid> - 2025-08-06 10:35 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-06 11:38 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-07 00:06 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-11 11:50 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-11 22:02 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-12 08:39 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-12 10:49 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use The Natural Philosopher <tnp@invalid.invalid> - 2025-08-12 10:54 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Charlie Gibbs <cgibbs@kltpzyxm.invalid> - 2025-08-12 18:47 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-12 23:36 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E. R." <robin_listas@es.invalid> - 2025-08-12 12:08 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use rbowman <bowman@montana.com> - 2025-08-12 19:35 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-12 23:07 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-13 09:47 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-14 00:41 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E.R." <robin_listas@es.invalid> - 2025-08-19 12:35 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-19 12:18 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-19 15:16 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-20 01:02 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-27 06:56 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-28 00:50 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-28 09:40 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-29 00:56 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use John Ames <commodorejohn@gmail.com> - 2025-08-29 08:10 -0700
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-29 19:16 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Tauno Voipio <tauno.voipio@notused.fi.invalid> - 2025-08-30 16:59 +0300
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-08-30 18:45 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Tauno Voipio <tauno.voipio@notused.fi.invalid> - 2025-08-31 21:24 +0300
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Mike Scott <usenet.16@scottsonline.org.uk.invalid> - 2025-09-01 17:02 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-31 03:25 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-30 06:34 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Nuno Silva <nunojsilva@invalid.invalid> - 2025-08-30 08:39 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use The Natural Philosopher <tnp@invalid.invalid> - 2025-08-30 08:45 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Harold Stevens <wookie@trixie.localdomain> - 2025-08-30 05:37 -0500
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use John Ames <commodorejohn@gmail.com> - 2025-09-02 09:59 -0700
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Harold Stevens <wookie@aspen.localdomain> - 2025-09-02 12:59 -0500
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Richard Kettlewell <invalid@invalid.invalid> - 2025-08-30 17:48 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-20 01:01 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E.R." <robin_listas@es.invalid> - 2025-08-20 12:52 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-20 22:36 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E.R." <robin_listas@es.invalid> - 2025-08-21 11:44 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use The Natural Philosopher <tnp@invalid.invalid> - 2025-08-21 11:34 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E.R." <robin_listas@es.invalid> - 2025-08-21 14:36 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Nuno Silva <nunojsilva@invalid.invalid> - 2025-08-21 14:27 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E.R." <robin_listas@es.invalid> - 2025-08-21 21:37 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Nuno Silva <nunojsilva@invalid.invalid> - 2025-08-22 10:33 +0100
Manuals [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-22 12:39 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-22 01:12 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-22 01:06 +0000
Documentation [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-22 12:26 +0200
Re: Documentation [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-23 23:13 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use John Ames <commodorejohn@gmail.com> - 2025-08-20 07:47 -0700
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-20 22:37 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Stéphane CARPENTIER <sc@fiat-linux.fr> - 2025-08-20 19:25 +0000
tldr [WAS: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-21 12:04 +0200
Re: tldr [WAS: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Stéphane CARPENTIER <sc@fiat-linux.fr> - 2025-08-23 12:40 +0000
Re: tldr [WAS: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-24 00:40 +0200
Re: tldr [WAS: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-23 23:15 +0000
Re: tldr [WAS: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Stéphane CARPENTIER <sc@fiat-linux.fr> - 2025-08-24 11:22 +0000
Re: tldr [WAS: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-24 22:18 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Anssi Saari <anssi.saari@usenet.mail.kapsi.fi> - 2025-08-21 12:40 +0300
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Richard Kettlewell <invalid@invalid.invalid> - 2025-08-06 14:21 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use The Natural Philosopher <tnp@invalid.invalid> - 2025-08-06 16:24 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use The Natural Philosopher <tnp@invalid.invalid> - 2025-08-06 10:12 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Anssi Saari <anssi.saari@usenet.mail.kapsi.fi> - 2025-08-07 11:43 +0300
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use John McCue <jmclnx@gmail.com.invalid> - 2025-08-06 11:55 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-06 07:40 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-06 06:31 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-06 11:06 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Richard Kettlewell <invalid@invalid.invalid> - 2025-08-06 14:25 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-06 17:11 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-06 23:59 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-07 08:37 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-07 06:52 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Rich <rich@example.invalid> - 2025-08-18 16:49 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E.R." <robin_listas@es.invalid> - 2025-08-06 12:46 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D'Oliveiro <ldo@nz.invalid> - 2025-08-06 23:56 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use "Carlos E.R." <robin_listas@es.invalid> - 2025-08-19 12:41 +0200
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-20 01:07 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Nuno Silva <nunojsilva@invalid.invalid> - 2025-08-20 09:48 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use The Natural Philosopher <tnp@invalid.invalid> - 2025-08-20 11:13 +0100
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-20 22:40 +0000
Re: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use vallor <vallor@cultnix.org> - 2025-08-21 00:27 +0000
ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-20 13:04 +0200
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] The Natural Philosopher <tnp@invalid.invalid> - 2025-08-20 12:30 +0100
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-20 22:44 +0000
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-21 12:15 +0200
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-22 01:18 +0000
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-22 12:45 +0200
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] The Natural Philosopher <tnp@invalid.invalid> - 2025-08-22 19:37 +0100
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] "Carlos E.R." <robin_listas@es.invalid> - 2025-08-22 22:32 +0200
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] The Natural Philosopher <tnp@invalid.invalid> - 2025-08-22 21:56 +0100
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-23 00:28 +0000
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] rbowman <bowman@montana.com> - 2025-08-23 05:51 +0000
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] The Natural Philosopher <tnp@invalid.invalid> - 2025-08-23 11:23 +0100
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-23 23:12 +0000
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] candycanearter07 <candycanearter07@candycanearter07.nomail.afraid> - 2025-08-29 19:40 +0000
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] rbowman <bowman@montana.com> - 2025-08-30 05:59 +0000
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-30 06:36 +0000
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Marc Haber <mh+usenetspam1118@zugschl.us> - 2025-08-30 10:36 +0200
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] Lawrence D’Oliveiro <ldo@nz.invalid> - 2025-08-31 01:25 +0000
Re: ISP router [Was: Yes, You Need A Firewall On Linux - Here’s Why And Which To Use] rbowman <bowman@montana.com> - 2025-08-23 05:43 +0000
Page 2 of 6 — ← Prev page 1 [2] 3 4 5 6 Next page →
| From | Lawrence D'Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2025-08-12 23:36 +0000 |
| Message-ID | <107gj5m$3jnlt$1@dont-email.me> |
| In reply to | #70850 |
On Tue, 12 Aug 2025 10:54:57 +0100, The Natural Philosopher wrote: > Life is too short to read the whole manual cover to cover. It helps to learn to speed-read. That man page has about 24,000 words in it, and as I said, it only took a few minutes to find the info I needed. Start by learning how to read without your lips moving.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E. R." <robin_listas@es.invalid> |
|---|---|
| Date | 2025-08-12 12:08 +0200 |
| Message-ID | <mg0i51Fi0gkU1@mid.individual.net> |
| In reply to | #70838 |
On 2025-08-12 09:39, Mike Scott wrote:
> On 11/08/2025 23:02, Lawrence D'Oliveiro wrote:
>> I don’t know. I’m just able to read documentation. I thought that was a
>> skill that was so commonplace among folks who work with computers for a
>> living that you could take it for granted, but apparently not.
>
> The horror is manuals written by the code-writer. They describe in
> intimate detail each and every function; but not how it all hooks up. In
> this case, I'd not even seen the nft man page, because I'd been
> searching for the wrong terms, hadn't got there because I'd got drowned
> in a morass of ipfilter and similar stuff, now apparently out-of-date;
> and gave it up as a bad job.
>
> What's wrong with a couple of clear examples, plus the detail to expand
> on them?
>
man pages are often terrible, with some exceptions. A list of options
and command is not a proper manual. At least a few examples are needed.
Instructions on how to achieve goals.
--
Cheers,
Carlos E.R.
[toc] | [prev] | [next] | [standalone]
| From | rbowman <bowman@montana.com> |
|---|---|
| Date | 2025-08-12 19:35 +0000 |
| Message-ID | <mg1jcqFnvhpU8@mid.individual.net> |
| In reply to | #70838 |
On Tue, 12 Aug 2025 08:39:44 +0100, Mike Scott wrote: > On 11/08/2025 23:02, Lawrence D'Oliveiro wrote: >> I don’t know. I’m just able to read documentation. I thought that was a >> skill that was so commonplace among folks who work with computers for a >> living that you could take it for granted, but apparently not. > > The horror is manuals written by the code-writer. They describe in > intimate detail each and every function; but not how it all hooks up. In > this case, I'd not even seen the nft man page, because I'd been > searching for the wrong terms, hadn't got there because I'd got drowned > in a morass of ipfilter and similar stuff, now apparently out-of-date; > and gave it up as a bad job. > > What's wrong with a couple of clear examples, plus the detail to expand > on them? We had a tech writer whose contribution to the documentation was pasting in the programmer's fix notes. That worked out great. It's sad she died young but at least we got a real tech writer after that. Her ongoing background task was translating the existing documents into English from Nerdese.
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D'Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2025-08-12 23:07 +0000 |
| Message-ID | <107ghgc$3j56j$3@dont-email.me> |
| In reply to | #70838 |
On Tue, 12 Aug 2025 08:39:44 +0100, Mike Scott wrote: > In this case, I'd not even seen the nft man page, because I'd been > searching for the wrong terms, hadn't got there because I'd got > drowned in a morass of ipfilter and similar stuff, now apparently > out-of-date; and gave it up as a bad job. You should know by now, that one of the first resorts when trying to find info on important Linux/BSD/*nix subsystems/APIs is to look for man pages. I have the feeling you didn’t even bother doing a web search, because ... > What's wrong with a couple of clear examples, plus the detail to expand > on them? I just tried doing a Google search for “nftables”, and guess what I found ...
[toc] | [prev] | [next] | [standalone]
| From | Mike Scott <usenet.16@scottsonline.org.uk.invalid> |
|---|---|
| Date | 2025-08-13 09:47 +0100 |
| Message-ID | <107hjf4$3pv2v$1@dont-email.me> |
| In reply to | #70870 |
On 13/08/2025 00:07, Lawrence D'Oliveiro wrote: > I have the feeling you didn’t even bother doing a web search, because ... Well, you'd better distrust your feelings then. Web searches are fine if you know relevant keywords. Meanwhile, welcome to the block list. Possible the first ever. -- Mike Scott Harlow, England
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D'Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2025-08-14 00:41 +0000 |
| Message-ID | <107jbb1$6imt$7@dont-email.me> |
| In reply to | #70895 |
On Wed, 13 Aug 2025 09:47:32 +0100, Mike Scott wrote: > On 13/08/2025 00:07, Lawrence D'Oliveiro wrote: >> >> I have the feeling you didn’t even bother doing a web search ... > > Well, you'd better distrust your feelings then. Web searches are > fine if you know relevant keywords. You mean, you didn’t try “nftables” as a search keyword? Because the very first hit Google gave me for that was ... <https://wiki.nftables.org/wiki-nftables/index.php/Main_Page>
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2025-08-19 12:35 +0200 |
| Message-ID | <9l0enlx168.ln2@Telcontar.valinor> |
| In reply to | #70838 |
On 2025-08-12 09:39, Mike Scott wrote: > On 11/08/2025 23:02, Lawrence D'Oliveiro wrote: >> I don’t know. I’m just able to read documentation. I thought that was a >> skill that was so commonplace among folks who work with computers for a >> living that you could take it for granted, but apparently not. > > The horror is manuals written by the code-writer. They describe in > intimate detail each and every function; but not how it all hooks up. In > this case, I'd not even seen the nft man page, because I'd been > searching for the wrong terms, hadn't got there because I'd got drowned > in a morass of ipfilter and similar stuff, now apparently out-of-date; > and gave it up as a bad job. > > What's wrong with a couple of clear examples, plus the detail to expand > on them? > +1 -- Cheers, Carlos.
[toc] | [prev] | [next] | [standalone]
| From | Mike Scott <usenet.16@scottsonline.org.uk.invalid> |
|---|---|
| Date | 2025-08-19 12:18 +0100 |
| Message-ID | <1081mho$3mu3b$1@dont-email.me> |
| In reply to | #71642 |
On 19/08/2025 11:35, Carlos E.R. wrote: > On 2025-08-12 09:39, Mike Scott wrote: >> On 11/08/2025 23:02, Lawrence D'Oliveiro wrote: >>> I don’t know. I’m just able to read documentation. I thought that was a >>> skill that was so commonplace among folks who work with computers for a >>> living that you could take it for granted, but apparently not. >> >> The horror is manuals written by the code-writer. They describe in >> intimate detail each and every function; but not how it all hooks up. >> In this case, I'd not even seen the nft man page, because I'd been >> searching for the wrong terms, hadn't got there because I'd got >> drowned in a morass of ipfilter and similar stuff, now apparently out- >> of-date; and gave it up as a bad job. >> >> What's wrong with a couple of clear examples, plus the detail to >> expand on them? >> > > +1 > Having been pointed at nftables as the right direction, I had a word with chatgpt asking for examples for my use case. I treat the answers with suspicion, but they seem clear and reasonable, and I'll take a good look when I've time. (I'd given up on chatgpt ages ago, when it made Noddy mistakes on trivial code examples. Looks like things have improved since then.) Thanks all for helpful answers. -- Mike Scott Harlow, England
[toc] | [prev] | [next] | [standalone]
| From | Marc Haber <mh+usenetspam1118@zugschl.us> |
|---|---|
| Date | 2025-08-19 15:16 +0200 |
| Message-ID | <1081tfb$27uo$1@news1.tnib.de> |
| In reply to | #71645 |
Mike Scott <usenet.16@scottsonline.org.uk.invalid> wrote: >(I'd given up on chatgpt ages ago, when it made Noddy mistakes on >trivial code examples. Looks like things have improved since then.) It still does make noddy mistakes. I recently asked it for a regexp that will cover all integers between 0 and 2^32-1, it didn't even get the parenthesis matched right. Greetings Marc -- ---------------------------------------------------------------------------- Marc Haber | " Questions are the | Mailadresse im Header Rhein-Neckar, DE | Beginning of Wisdom " | Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2025-08-20 01:02 +0000 |
| Message-ID | <10836qt$1m96$12@dont-email.me> |
| In reply to | #71661 |
On Tue, 19 Aug 2025 15:16:26 +0200, Marc Haber wrote: > It still does make noddy mistakes. In other news, a survey reports that, the less confidence developers have in AI, the more they use it.
[toc] | [prev] | [next] | [standalone]
| From | Mike Scott <usenet.16@scottsonline.org.uk.invalid> |
|---|---|
| Date | 2025-08-27 06:56 +0100 |
| Message-ID | <108m6mu$fe1a$1@dont-email.me> |
| In reply to | #71645 |
On 19/08/2025 12:18, Mike Scott wrote: > Having been pointed at nftables as the right direction, I had a word > with chatgpt asking for examples for my use case. I treat the answers > with suspicion, but they seem clear and reasonable, and I'll take a good > look when I've time. > > (I'd given up on chatgpt ages ago, when it made Noddy mistakes on > trivial code examples. Looks like things have improved since then.) > > Thanks all for helpful answers. Sorry for following up my own message, but..... I tried the chatgpt-generated nft config file yesterday. Interesting. It had a grossw syntactical error in it. I flagged this up to chatgpt, which apologised (!) and gave a slightly modified version. Same problem. I flagged it up again: it went away for almost 3 minutes, chuntering about checking things and "thinking". It came back with a decidedly modified version that had correct syntax. I told it to explain its error, and it said it had got muddled between nft and sh script syntax. Hmm. Anyway, the upshot is that I seem to have been right about nft's limitations compared to pf. It's concept of "set" (analogous to pf' "table" looks to have a huge issue. pf allows, for example pfctl -t inboundblock -T replace -f /etc/firewall/inboundblock which is an atomic operation. AFAICT, with nft you have to operate element-by-element, and cannot load a set from a file of wanted elements, nor clear nor replace the contents as a group. Is this correct? -- Mike Scott Harlow, England
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2025-08-28 00:50 +0000 |
| Message-ID | <108o94p$10pj9$8@dont-email.me> |
| In reply to | #72373 |
On Wed, 27 Aug 2025 06:56:46 +0100, Mike Scott wrote:
> pf allows, for example
> pfctl -t inboundblock -T replace -f /etc/firewall/inboundblock
> which is an atomic operation.
The docs say
nft -f «file»
is an atomic operation. You might have known that if you’d read them.
[toc] | [prev] | [next] | [standalone]
| From | Mike Scott <usenet.16@scottsonline.org.uk.invalid> |
|---|---|
| Date | 2025-08-28 09:40 +0100 |
| Message-ID | <108p4m2$173fr$1@dont-email.me> |
| In reply to | #72447 |
On 28/08/2025 01:50, Lawrence D’Oliveiro wrote: > On Wed, 27 Aug 2025 06:56:46 +0100, Mike Scott wrote: > >> pf allows, for example >> pfctl -t inboundblock -T replace -f /etc/firewall/inboundblock >> which is an atomic operation. > > The docs say > > nft -f «file» > > is an atomic operation. You might have known that if you’d read them. > man nft |grep atomic troff:<standard input>:1317: warning [p 10, 4.7i, div '3tbd9,1', 0.3i]: cannot break line troff:<standard input>:6498: warning [p 27, 0.3i, div '3tbd10,0', 0.2i]: cannot break line <standard input>:6352: warning: table wider than line length minus indentation troff:<standard input>:8857: warning [p 32, 0.3i, div '3tbd1,1', 0.3i]: cannot break line To be fair, the online wiki does give the answer. Which raises the issue, again, of documentation standards. When important matters are absent from at least some key docs, then what? There's more to life than grubbing around on the net hoping to hit the right combination of keywords. Again, I asked chatgpt about this (hindsight is so good), and it came up with helpful information. -- Mike Scott Harlow, England
[toc] | [prev] | [next] | [standalone]
| From | Lawrence D’Oliveiro <ldo@nz.invalid> |
|---|---|
| Date | 2025-08-29 00:56 +0000 |
| Message-ID | <108qtsm$1n18s$5@dont-email.me> |
| In reply to | #72482 |
On Thu, 28 Aug 2025 09:40:34 +0100, Mike Scott wrote: > To be fair, the online wiki does give the answer. Which raises the > issue, again, of documentation standards. When important matters are > absent from at least some key docs, then what? Weren’t you one of those complaining that bare reference material wasn’t enough? That you wanted tutorial examples and how-tos and all that? Then when I mention that it all that is available, you now find a new reason to complain?
[toc] | [prev] | [next] | [standalone]
| From | John Ames <commodorejohn@gmail.com> |
|---|---|
| Date | 2025-08-29 08:10 -0700 |
| Message-ID | <20250829081008.00004d8a@gmail.com> |
| In reply to | #72566 |
On Fri, 29 Aug 2025 00:56:54 -0000 (UTC) Lawrence D’Oliveiro <ldo@nz.invalid> wrote: > > To be fair, the online wiki does give the answer. Which raises the > > issue, again, of documentation standards. When important matters are > > absent from at least some key docs, then what? > > Weren’t you one of those complaining that bare reference material > wasn’t enough? That you wanted tutorial examples and how-tos and all > that? Then when I mention that it all that is available, you now find > a new reason to complain? Again, when important information for *core networking tools* is only found on the Web, it hardly takes a great sage to discern the problem.
[toc] | [prev] | [next] | [standalone]
| From | Mike Scott <usenet.16@scottsonline.org.uk.invalid> |
|---|---|
| Date | 2025-08-29 19:16 +0100 |
| Message-ID | <108sqqi$25aq9$1@dont-email.me> |
| In reply to | #72641 |
On 29/08/2025 16:10, John Ames wrote: > On Fri, 29 Aug 2025 00:56:54 -0000 (UTC) > Lawrence D’Oliveiro <ldo@nz.invalid> wrote: > >>> To be fair, the online wiki does give the answer. Which raises the >>> issue, again, of documentation standards. When important matters are >>> absent from at least some key docs, then what? >> >> Weren’t you one of those complaining that bare reference material >> wasn’t enough? That you wanted tutorial examples and how-tos and all >> that? Then when I mention that it all that is available, you now find >> a new reason to complain? > > Again, when important information for *core networking tools* is only > found on the Web, it hardly takes a great sage to discern the problem. > The problem is that it is /not/ all available. I'm quite stumped about one particular issue for which there seem no references at all that I can find: and believe me, I have looked. Ironically, chatgpt has been a help. It makes so many errors that sorting them out has been quite educational. Oh - the problem in hand. No doubt it's easy when you know: single interface, allow all lan traffic, block wan inbound to port 22, redirect wan inbound on port 12345 to 22 and pass. Block wan inbound otherwise. If anyone has a config snippet to do this, I'd be very grateful. -- Mike Scott Harlow, England
[toc] | [prev] | [next] | [standalone]
| From | Tauno Voipio <tauno.voipio@notused.fi.invalid> |
|---|---|
| Date | 2025-08-30 16:59 +0300 |
| Message-ID | <108v04h$2koah$1@dont-email.me> |
| In reply to | #72656 |
On 29.8.2025 21.16, Mike Scott wrote: > On 29/08/2025 16:10, John Ames wrote: >> On Fri, 29 Aug 2025 00:56:54 -0000 (UTC) >> Lawrence D’Oliveiro <ldo@nz.invalid> wrote: >> >>>> To be fair, the online wiki does give the answer. Which raises the >>>> issue, again, of documentation standards. When important matters are >>>> absent from at least some key docs, then what? >>> >>> Weren’t you one of those complaining that bare reference material >>> wasn’t enough? That you wanted tutorial examples and how-tos and all >>> that? Then when I mention that it all that is available, you now find >>> a new reason to complain? >> >> Again, when important information for *core networking tools* is only >> found on the Web, it hardly takes a great sage to discern the problem. >> > > The problem is that it is /not/ all available. I'm quite stumped about > one particular issue for which there seem no references at all that I > can find: and believe me, I have looked. > > Ironically, chatgpt has been a help. It makes so many errors that > sorting them out has been quite educational. > > Oh - the problem in hand. No doubt it's easy when you know: single > interface, allow all lan traffic, block wan inbound to port 22, redirect > wan inbound on port 12345 to 22 and pass. Block wan inbound otherwise. > If anyone has a config snippet to do this, I'd be very grateful. > > Mike, The tool you need is called nftables, with a command line interface program called nft. Google for nftables documentation, read and understand it, the response is there with examples. It is difficult to provide a good snippet without your networking details. You could also configure the ssh daemon with a secondary port of 12345, just pass it, to avoid the port translation step. -- -TV
[toc] | [prev] | [next] | [standalone]
| From | Mike Scott <usenet.16@scottsonline.org.uk.invalid> |
|---|---|
| Date | 2025-08-30 18:45 +0100 |
| Message-ID | <108vdc2$2ohi5$1@dont-email.me> |
| In reply to | #72757 |
On 30/08/2025 14:59, Tauno Voipio wrote: > On 29.8.2025 21.16, Mike Scott wrote: >> On 29/08/2025 16:10, John Ames wrote: >>> On Fri, 29 Aug 2025 00:56:54 -0000 (UTC) >>> Lawrence D’Oliveiro <ldo@nz.invalid> wrote: >>> >>>>> To be fair, the online wiki does give the answer. Which raises the >>>>> issue, again, of documentation standards. When important matters are >>>>> absent from at least some key docs, then what? >>>> >>>> Weren’t you one of those complaining that bare reference material >>>> wasn’t enough? That you wanted tutorial examples and how-tos and all >>>> that? Then when I mention that it all that is available, you now find >>>> a new reason to complain? >>> >>> Again, when important information for *core networking tools* is only >>> found on the Web, it hardly takes a great sage to discern the problem. >>> >> >> The problem is that it is /not/ all available. I'm quite stumped about >> one particular issue for which there seem no references at all that I >> can find: and believe me, I have looked. >> >> Ironically, chatgpt has been a help. It makes so many errors that >> sorting them out has been quite educational. >> >> Oh - the problem in hand. No doubt it's easy when you know: single >> interface, allow all lan traffic, block wan inbound to port 22, >> redirect wan inbound on port 12345 to 22 and pass. Block wan inbound >> otherwise. If anyone has a config snippet to do this, I'd be very >> grateful. >> >> > > Mike, > > The tool you need is called nftables, with a command line > interface program called nft. > > Google for nftables documentation, read and understand it, the > response is there with examples. It is difficult to provide a > good snippet without your networking details. > > You could also configure the ssh daemon with a secondary port > of 12345, just pass it, to avoid the port translation step. > We're going in circles here.... there's an issue with lack of decent docs (and examples) for nft - it seems that port blocking occurs after the redirection, with unhappy consequences, and I find no usable information suggesting any other possibility. I have running on freebsd, and am trying to move to linux, a server that ignores port 22 from the net at large, but accepts (similar to) 12345, just to provide an extra layer of obfuscation to wannabe attackers. It's a 2-line doddle on freebsd's pf firewall; I can't for the life of me work out the nftables equivalent, and begin to wonder if indeed it can be done. I suppose opening multiple ssh listener ports is another solution (thanks), but the original problem should - surely - be solvable: it also pops up for other services but which won't necessarily have the workaround. -- Mike Scott Harlow, England
[toc] | [prev] | [next] | [standalone]
| From | Tauno Voipio <tauno.voipio@notused.fi.invalid> |
|---|---|
| Date | 2025-08-31 21:24 +0300 |
| Message-ID | <109241p$3cnp8$1@dont-email.me> |
| In reply to | #72766 |
On 30.8.2025 20.45, Mike Scott wrote: > On 30/08/2025 14:59, Tauno Voipio wrote: >> On 29.8.2025 21.16, Mike Scott wrote: >>> On 29/08/2025 16:10, John Ames wrote: >>>> On Fri, 29 Aug 2025 00:56:54 -0000 (UTC) >>>> Lawrence D’Oliveiro <ldo@nz.invalid> wrote: >>>> >>>>>> To be fair, the online wiki does give the answer. Which raises the >>>>>> issue, again, of documentation standards. When important matters are >>>>>> absent from at least some key docs, then what? >>>>> >>>>> Weren’t you one of those complaining that bare reference material >>>>> wasn’t enough? That you wanted tutorial examples and how-tos and all >>>>> that? Then when I mention that it all that is available, you now find >>>>> a new reason to complain? >>>> >>>> Again, when important information for *core networking tools* is only >>>> found on the Web, it hardly takes a great sage to discern the problem. >>>> >>> >>> The problem is that it is /not/ all available. I'm quite stumped >>> about one particular issue for which there seem no references at all >>> that I can find: and believe me, I have looked. >>> >>> Ironically, chatgpt has been a help. It makes so many errors that >>> sorting them out has been quite educational. >>> >>> Oh - the problem in hand. No doubt it's easy when you know: single >>> interface, allow all lan traffic, block wan inbound to port 22, >>> redirect wan inbound on port 12345 to 22 and pass. Block wan inbound >>> otherwise. If anyone has a config snippet to do this, I'd be very >>> grateful. >>> >>> >> >> Mike, >> >> The tool you need is called nftables, with a command line >> interface program called nft. >> >> Google for nftables documentation, read and understand it, the >> response is there with examples. It is difficult to provide a >> good snippet without your networking details. >> >> You could also configure the ssh daemon with a secondary port >> of 12345, just pass it, to avoid the port translation step. >> > > We're going in circles here.... there's an issue with lack of decent > docs (and examples) for nft - it seems that port blocking occurs after > the redirection, with unhappy consequences, and I find no usable > information suggesting any other possibility. > > I have running on freebsd, and am trying to move to linux, a server that > ignores port 22 from the net at large, but accepts (similar to) 12345, > just to provide an extra layer of obfuscation to wannabe attackers. > > It's a 2-line doddle on freebsd's pf firewall; I can't for the life of > me work out the nftables equivalent, and begin to wonder if indeed it > can be done. > > I suppose opening multiple ssh listener ports is another solution > (thanks), but the original problem should - surely - be solvable: it > also pops up for other services but which won't necessarily have the > workaround. I'm writing this just on a network, where the Linux router is having a ruleset resembling what you ask for. Please look at <https://wiki.nftables.org/wiki-nftables/index.php/Netfilter_hooks> The nftables pages contain the information you need. You need to block the inbound TCP port 22 coming from the external interface. The correct place is in the ip nat table, PREROUTING chain. -- -TV
[toc] | [prev] | [next] | [standalone]
| From | Mike Scott <usenet.16@scottsonline.org.uk.invalid> |
|---|---|
| Date | 2025-09-01 17:02 +0100 |
| Message-ID | <1094g30$3uuca$1@dont-email.me> |
| In reply to | #72837 |
On 31/08/2025 19:24, Tauno Voipio wrote:
> On 30.8.2025 20.45, Mike Scott wrote:
>> On 30/08/2025 14:59, Tauno Voipio wrote:
>>> On 29.8.2025 21.16, Mike Scott wrote:
>>>> On 29/08/2025 16:10, John Ames wrote:
>>>>> On Fri, 29 Aug 2025 00:56:54 -0000 (UTC)
>>>>> Lawrence D’Oliveiro <ldo@nz.invalid> wrote:
>>>>>
>>>>>>> To be fair, the online wiki does give the answer. Which raises the
>>>>>>> issue, again, of documentation standards. When important matters are
>>>>>>> absent from at least some key docs, then what?
>>>>>>
>>>>>> Weren’t you one of those complaining that bare reference material
>>>>>> wasn’t enough? That you wanted tutorial examples and how-tos and all
>>>>>> that? Then when I mention that it all that is available, you now find
>>>>>> a new reason to complain?
>>>>>
>>>>> Again, when important information for *core networking tools* is only
>>>>> found on the Web, it hardly takes a great sage to discern the problem.
>>>>>
>>>>
>>>> The problem is that it is /not/ all available. I'm quite stumped
>>>> about one particular issue for which there seem no references at all
>>>> that I can find: and believe me, I have looked.
>>>>
>>>> Ironically, chatgpt has been a help. It makes so many errors that
>>>> sorting them out has been quite educational.
>>>>
>>>> Oh - the problem in hand. No doubt it's easy when you know: single
>>>> interface, allow all lan traffic, block wan inbound to port 22,
>>>> redirect wan inbound on port 12345 to 22 and pass. Block wan inbound
>>>> otherwise. If anyone has a config snippet to do this, I'd be very
>>>> grateful.
>>>>
>>>>
>>>
>>> Mike,
>>>
>>> The tool you need is called nftables, with a command line
>>> interface program called nft.
>>>
>>> Google for nftables documentation, read and understand it, the
>>> response is there with examples. It is difficult to provide a
>>> good snippet without your networking details.
>>>
>>> You could also configure the ssh daemon with a secondary port
>>> of 12345, just pass it, to avoid the port translation step.
>>>
>>
>> We're going in circles here.... there's an issue with lack of decent
>> docs (and examples) for nft - it seems that port blocking occurs after
>> the redirection, with unhappy consequences, and I find no usable
>> information suggesting any other possibility.
>>
>> I have running on freebsd, and am trying to move to linux, a server
>> that ignores port 22 from the net at large, but accepts (similar to)
>> 12345, just to provide an extra layer of obfuscation to wannabe
>> attackers.
>>
>> It's a 2-line doddle on freebsd's pf firewall; I can't for the life of
>> me work out the nftables equivalent, and begin to wonder if indeed it
>> can be done.
>>
>> I suppose opening multiple ssh listener ports is another solution
>> (thanks), but the original problem should - surely - be solvable: it
>> also pops up for other services but which won't necessarily have the
>> workaround.
>
>
> I'm writing this just on a network, where the Linux router is having
> a ruleset resembling what you ask for.
>
> Please look at <https://wiki.nftables.org/wiki-nftables/index.php/
> Netfilter_hooks>
>
> The nftables pages contain the information you need.
>
> You need to block the inbound TCP port 22 coming from the external
> interface. The correct place is in the ip nat table, PREROUTING chain.
>
Thank you for the reply. I can't say that the page you offer is
particularly enlightening.
However, after grubbing around yet more and with trial and error I have
a way of doing it:
table inet filter {
chain input {
......
# Reject direct SSH (port 22) from WAN
tcp dport 21022 drop
tcp dport 22 accept
...
}
}
table inet nat {
chain prerouting {
type nat hook prerouting priority -100;
# DNAT: Redirect WAN port 12345 to local port 22, WAN port 22
to graveyard
tcp dport 12345 ip saddr != 192.168.0.0/24 dnat ip to :22
tcp dport 22 ip saddr != 192.168.0.0/24 dnat ip to :21022
}
}
The solution involves the seemingly undocumented use of "!=" in this
context. (It seems to mean "is contained in" but IMBW. If anyone knows
where this is described, I'd be grateful. Or if it's wrong!)
--
Mike Scott
Harlow, England
[toc] | [prev] | [next] | [standalone]
Page 2 of 6 — ← Prev page 1 [2] 3 4 5 6 Next page →
Back to top | Article view | comp.os.linux.misc
csiph-web