Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #265846
| From | Ralph Aichinger <ra@h5.or.at> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: nftables firewall question: matching udp in ipv6 |
| Date | 2024-01-12 19:10 +0100 |
| Message-ID | <HVu8F-2Dcd-7@gated-at.bofh.it> (permalink) |
| References | <HVrNw-2BEZ-21@gated-at.bofh.it> <HVtvX-2CJe-5@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Fri, Jan 12, 2024 at 05:26:57PM +0000, Michael Kjörling wrote: > My suggestion would be to insert a "udp log" rule. (Pretty sure you > only need "udp", not "meta l4proto udp".) Thanks, I will try that. Yes "meta l4proto udp" might be cargo cult configuration ;) > That will give you a firehose of information which will include ports, > interfaces and other relevant information. You can then narrow it down > until it logs the traffic you want to accept, at which point you can > change the "log" action into an "accept" action. > > Note that forwarding and filtering can interact in non-intuitive ways. > You may need to add corresponding log rules to each relevant chain, > maybe with a prefix to tell them apart. Thanks a lot! Ralph
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 16:40 +0100
Re: nftables firewall question: matching udp in ipv6 Tom Furie <tom@furie.org.uk> - 2024-01-12 17:00 +0100
Re: nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 17:30 +0100
Re: nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 17:40 +0100
Re: nftables firewall question: matching udp in ipv6 Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-01-12 18:30 +0100
Re: nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 19:10 +0100
Re: nftables firewall question: matching udp in ipv6 Michel Verdier <mv524@free.fr> - 2024-01-12 19:40 +0100
Re: nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 21:20 +0100
Re: nftables firewall question: matching udp in ipv6 Michel Verdier <mv524@free.fr> - 2024-01-12 22:10 +0100
csiph-web