Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #241084 > unrolled thread
| Started by | Tim Woodall <debianuser@woodall.me.uk> |
|---|---|
| First post | 2021-10-10 13:10 +0200 |
| Last post | 2021-10-11 11:00 +0200 |
| Articles | 5 — 4 participants |
Back to article view | Back to linux.debian.user
ip6tables rule being rejected. Tim Woodall <debianuser@woodall.me.uk> - 2021-10-10 13:10 +0200
Re: ip6tables rule being rejected. Markus Schönhaber <debian-user@list-post.mks-mail.de> - 2021-10-10 14:30 +0200
Re: ip6tables rule being rejected. Reco <recoverym4n@enotuniq.net> - 2021-10-10 14:40 +0200
Re: ip6tables rule being rejected. Tim Woodall <debianuser@woodall.me.uk> - 2021-10-10 18:30 +0200
Re: ip6tables rule being rejected. Andrei POPESCU <andreimpopescu@gmail.com> - 2021-10-11 11:00 +0200
| From | Tim Woodall <debianuser@woodall.me.uk> |
|---|---|
| Date | 2021-10-10 13:10 +0200 |
| Subject | ip6tables rule being rejected. |
| Message-ID | <D6ESm-44O-5@gated-at.bofh.it> |
Hi,
When I try to add the following rule:
# ip6tables -t nat -A POSTROUTING -s 2001::/64 -d ! 2001:1::/64 -j ACCEPT
Bad argument `2001:1::/64'
Try `ip6tables -h' or 'ip6tables --help' for more information.
It is rejected. (Ignore the fact that this rule doesn't make a huge
amount of sense, it's a very cut down instance of the rule that I'm
really trying to add)
Leaving off the exclusion:
# ip6tables -t nat -A POSTROUTING -s 2001::/64 -d 2001:1::/64 -j ACCEPT
#
And there is no problem
The manpage suggests that it should work:
d, --destination [!] address[/mask]
Destination specification. See the description of the -s (source)
flag for a detailed description of the syntax. The flag --dst is an
alias for this option.
Am I doing something daft or should this work?
[toc] | [next] | [standalone]
| From | Markus Schönhaber <debian-user@list-post.mks-mail.de> |
|---|---|
| Date | 2021-10-10 14:30 +0200 |
| Message-ID | <D6G7L-4JL-3@gated-at.bofh.it> |
| In reply to | #241084 |
10.10.21, 13:06 +0200, Tim Woodall: > When I try to add the following rule: > > # ip6tables -t nat -A POSTROUTING -s 2001::/64 -d ! 2001:1::/64 -j ACCEPT > Bad argument `2001:1::/64' > Try `ip6tables -h' or 'ip6tables --help' for more information. > > It is rejected. (Ignore the fact that this rule doesn't make a huge > amount of sense, it's a very cut down instance of the rule that I'm > really trying to add) > > Leaving off the exclusion: > # ip6tables -t nat -A POSTROUTING -s 2001::/64 -d 2001:1::/64 -j ACCEPT > # > > And there is no problem > > The manpage suggests that it should work: > d, --destination [!] address[/mask] > Destination specification. See the description of the -s (source) > flag for a detailed description of the syntax. The flag --dst is an > alias for this option. The man page I see on bullseye suggests otherwise: > [!] -d, --destination address[/mask][,...] > Destination specification. See the description of the -s (source) flag for a detailed description of the syntax. The flag --dst is > an alias for this option. i. e. putting The '!' left of the '-d' works: # ip6tables -t nat -A POSTROUTING -s 2001::/64 ! -d 2001:1::/64 -j ACCEPT Granted, the explanation in the man page for "!" under "--source" seems a bit ambiguous to me: > [!] -s, --source address[/mask][,...] [...] > A "!" argument before the address specification inverts the sense of the address. The start of the paragraph shows where the "!" belongs, though. -- Regards mks
[toc] | [prev] | [next] | [standalone]
| From | Reco <recoverym4n@enotuniq.net> |
|---|---|
| Date | 2021-10-10 14:40 +0200 |
| Message-ID | <D6Ghs-4MT-7@gated-at.bofh.it> |
| In reply to | #241084 |
Hi. On Sun, Oct 10, 2021 at 12:06:25PM +0100, Tim Woodall wrote: > When I try to add the following rule: > > # ip6tables -t nat -A POSTROUTING -s 2001::/64 -d ! 2001:1::/64 -j ACCEPT > Bad argument `2001:1::/64' > Try `ip6tables -h' or 'ip6tables --help' for more information. > > It is rejected. As it should. This is correct one: ip6tables -t nat -A POSTROUTING -s 2001::/64 ! -d 2001:1::/64 -j ACCEPT It's a known quirk of iptables - you apply inversion *before* the test, not *inside* of it. > And there is no problem > > The manpage suggests that it should work: > d, --destination [!] address[/mask] My instance of the same manpage states differently: [!] -d, --destination address[/mask][,...] But I'm using current stable, I'm unsure how this quirk was documented before, but it behaved this was for two major Debian releases, maybe more. Reco
[toc] | [prev] | [next] | [standalone]
| From | Tim Woodall <debianuser@woodall.me.uk> |
|---|---|
| Date | 2021-10-10 18:30 +0200 |
| Message-ID | <D6JS1-6XL-3@gated-at.bofh.it> |
| In reply to | #241091 |
On Sun, 10 Oct 2021, Reco wrote: > On Sun, Oct 10, 2021 at 12:06:25PM +0100, Tim Woodall wrote: >> When I try to add the following rule: >> >> # ip6tables -t nat -A POSTROUTING -s 2001::/64 -d ! 2001:1::/64 -j ACCEPT >> Bad argument `2001:1::/64' >> Try `ip6tables -h' or 'ip6tables --help' for more information. >> >> It is rejected. > > As it should. This is correct one: > > ip6tables -t nat -A POSTROUTING -s 2001::/64 ! -d 2001:1::/64 -j ACCEPT > > It's a known quirk of iptables - you apply inversion *before* the test, > not *inside* of it. > >> And there is no problem >> >> The manpage suggests that it should work: >> d, --destination [!] address[/mask] > > My instance of the same manpage states differently: > > [!] -d, --destination address[/mask][,...] > > But I'm using current stable, I'm unsure how this quirk was documented > before, but it behaved this was for two major Debian releases, maybe > more. > Thanks both! It's now working. And, indeed, my manpage does have it the way you suggest. I'd initially found the documentation via a web search and not twigged that the manpage and the documenatation here were different: https://linux.die.net/man/8/ip6tables Tim.
[toc] | [prev] | [next] | [standalone]
| From | Andrei POPESCU <andreimpopescu@gmail.com> |
|---|---|
| Date | 2021-10-11 11:00 +0200 |
| Message-ID | <D6Zk6-8wm-1@gated-at.bofh.it> |
| In reply to | #241106 |
[Multipart message — attachments visible in raw view] — view raw
On Du, 10 oct 21, 17:19:52, Tim Woodall wrote: > > Thanks both! It's now working. And, indeed, my manpage does have it the > way you suggest. I'd initially found the documentation via a web search > and not twigged that the manpage and the documenatation here were > different: > > https://linux.die.net/man/8/ip6tables If you prefer reading manpages on the web you might want to use https://manpages.debian.org. That way you are looking at the manpage corresponding to your specific software and version[1]. It can be also be added as an alternative search engine to most common browsers. [1] Debian Developers patch manpages too occasionally, to document Debian specific changes, e.g. see the explanations for the -X and -Y switches in ssh(1). Kind regards, Andrei -- http://wiki.debian.org/FAQsFromDebianUser
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web