Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #241091

Re: ip6tables rule being rejected.

From Reco <recoverym4n@enotuniq.net>
Newsgroups linux.debian.user
Subject Re: ip6tables rule being rejected.
Date 2021-10-10 14:40 +0200
Message-ID <D6Ghs-4MT-7@gated-at.bofh.it> (permalink)
References <D6ESm-44O-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


	Hi.

On Sun, Oct 10, 2021 at 12:06:25PM +0100, Tim Woodall wrote:
> When I try to add the following rule:
> 
> # ip6tables -t nat -A POSTROUTING -s 2001::/64 -d ! 2001:1::/64 -j ACCEPT
> Bad argument `2001:1::/64'
> Try `ip6tables -h' or 'ip6tables --help' for more information.
> 
> It is rejected.

As it should. This is correct one:

ip6tables -t nat -A POSTROUTING -s 2001::/64 ! -d 2001:1::/64 -j ACCEPT

It's a known quirk of iptables - you apply inversion *before* the test,
not *inside* of it.

> And there is no problem
> 
> The manpage suggests that it should work:
> d, --destination [!] address[/mask]

My instance of the same manpage states differently:

[!] -d, --destination address[/mask][,...]

But I'm using current stable, I'm unsure how this quirk was documented
before, but it behaved this was for two major Debian releases, maybe
more.

Reco

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

ip6tables rule being rejected. Tim Woodall <debianuser@woodall.me.uk> - 2021-10-10 13:10 +0200
  Re: ip6tables rule being rejected. Markus Schönhaber <debian-user@list-post.mks-mail.de> - 2021-10-10 14:30 +0200
  Re: ip6tables rule being rejected. Reco <recoverym4n@enotuniq.net> - 2021-10-10 14:40 +0200
    Re: ip6tables rule being rejected. Tim Woodall <debianuser@woodall.me.uk> - 2021-10-10 18:30 +0200
      Re: ip6tables rule being rejected. Andrei POPESCU <andreimpopescu@gmail.com> - 2021-10-11 11:00 +0200

csiph-web