Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #241091
| From | Reco <recoverym4n@enotuniq.net> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: ip6tables rule being rejected. |
| Date | 2021-10-10 14:40 +0200 |
| Message-ID | <D6Ghs-4MT-7@gated-at.bofh.it> (permalink) |
| References | <D6ESm-44O-5@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Hi. On Sun, Oct 10, 2021 at 12:06:25PM +0100, Tim Woodall wrote: > When I try to add the following rule: > > # ip6tables -t nat -A POSTROUTING -s 2001::/64 -d ! 2001:1::/64 -j ACCEPT > Bad argument `2001:1::/64' > Try `ip6tables -h' or 'ip6tables --help' for more information. > > It is rejected. As it should. This is correct one: ip6tables -t nat -A POSTROUTING -s 2001::/64 ! -d 2001:1::/64 -j ACCEPT It's a known quirk of iptables - you apply inversion *before* the test, not *inside* of it. > And there is no problem > > The manpage suggests that it should work: > d, --destination [!] address[/mask] My instance of the same manpage states differently: [!] -d, --destination address[/mask][,...] But I'm using current stable, I'm unsure how this quirk was documented before, but it behaved this was for two major Debian releases, maybe more. Reco
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
ip6tables rule being rejected. Tim Woodall <debianuser@woodall.me.uk> - 2021-10-10 13:10 +0200
Re: ip6tables rule being rejected. Markus Schönhaber <debian-user@list-post.mks-mail.de> - 2021-10-10 14:30 +0200
Re: ip6tables rule being rejected. Reco <recoverym4n@enotuniq.net> - 2021-10-10 14:40 +0200
Re: ip6tables rule being rejected. Tim Woodall <debianuser@woodall.me.uk> - 2021-10-10 18:30 +0200
Re: ip6tables rule being rejected. Andrei POPESCU <andreimpopescu@gmail.com> - 2021-10-11 11:00 +0200
csiph-web