Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #228502

Re: Stretch => Buster: iptables

From Jesper Dybdal <jd-debian-user@dybdal.dk>
Newsgroups linux.debian.user
Subject Re: Stretch => Buster: iptables
Date 2020-11-06 12:10 +0100
Message-ID <B87N0-1gP-29@gated-at.bofh.it> (permalink)
References <B0v9L-4bV-1@gated-at.bofh.it> <B86xA-lp-1@gated-at.bofh.it> <B87tE-UE-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On 2020-11-06 11:43, Sven Hartge wrote:
> Jesper Dybdal <jd-debian-user@dybdal.dk> wrote:
>> * The CT target, to add the ftp helper.  I fixed that by adding a bit of
>> native nft with the nft command after all the iptables(-nft) commands.
> For the sake of the archive and people looking at this thread hoping for
> some insight, please post your native nft rules you created.

Here they are (I'm afraid I can't remember which websites I got the 
inspiration from):

table ip myhelpers {
         ct helper ftp-standard {
                 type "ftp" protocol tcp
         }
     chain input {
                 type filter hook prerouting priority 0;
                 tcp dport 21 ct helper set "ftp-standard" counter
         }
     chain output {
                 type filter hook output priority 0;
                 tcp dport 21 ct helper set "ftp-standard" counter
         }
}


I loaded them after all the iptables-nft rules with the commands:

# Delete any existing myhelpers tables, ignoring possible failure for an 
non-existent table:
nft delete table myhelpers >/dev/null 2>&1
# Load the myhelpers table shown above:
nft -f myhelpers.nft

This seems to work.

-- 
Jesper Dybdal
https://www.dybdal.dk

Back to linux.debian.user | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

Stretch => Buster: iptables Jesper Dybdal <jd-debian-user@dybdal.dk> - 2020-10-16 12:30 +0200
  Re: Stretch => Buster: iptables Reco <recoverym4n@enotuniq.net> - 2020-10-16 12:40 +0200
    Re: Stretch => Buster: iptables Jesper Dybdal <jd-debian-user@dybdal.dk> - 2020-10-16 14:20 +0200
      Re: Stretch => Buster: iptables Pierre-Elliott Bécue <peb@debian.org> - 2020-10-16 16:30 +0200
  Re: Stretch => Buster: iptables Jesper Dybdal <jd-debian-user@dybdal.dk> - 2020-11-06 10:50 +0100
    Re: Stretch => Buster: iptables Sven Hartge <sven@svenhartge.de> - 2020-11-06 11:50 +0100
      Re: Stretch => Buster: iptables Jesper Dybdal <jd-debian-user@dybdal.dk> - 2020-11-06 12:10 +0100

csiph-web