Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #241084 > unrolled thread

ip6tables rule being rejected.

Started byTim Woodall <debianuser@woodall.me.uk>
First post2021-10-10 13:10 +0200
Last post2021-10-11 11:00 +0200
Articles 5 — 4 participants

Back to article view | Back to linux.debian.user


Contents

  ip6tables rule being rejected. Tim Woodall <debianuser@woodall.me.uk> - 2021-10-10 13:10 +0200
    Re: ip6tables rule being rejected. Markus Schönhaber <debian-user@list-post.mks-mail.de> - 2021-10-10 14:30 +0200
    Re: ip6tables rule being rejected. Reco <recoverym4n@enotuniq.net> - 2021-10-10 14:40 +0200
      Re: ip6tables rule being rejected. Tim Woodall <debianuser@woodall.me.uk> - 2021-10-10 18:30 +0200
        Re: ip6tables rule being rejected. Andrei POPESCU <andreimpopescu@gmail.com> - 2021-10-11 11:00 +0200

#241084 — ip6tables rule being rejected.

FromTim Woodall <debianuser@woodall.me.uk>
Date2021-10-10 13:10 +0200
Subjectip6tables rule being rejected.
Message-ID<D6ESm-44O-5@gated-at.bofh.it>
Hi,

When I try to add the following rule:

# ip6tables -t nat -A POSTROUTING -s 2001::/64 -d ! 2001:1::/64 -j ACCEPT
Bad argument `2001:1::/64'
Try `ip6tables -h' or 'ip6tables --help' for more information.

It is rejected. (Ignore the fact that this rule doesn't make a huge
amount of sense, it's a very cut down instance of the rule that I'm
really trying to add)

Leaving off the exclusion:
# ip6tables -t nat -A POSTROUTING -s 2001::/64 -d 2001:1::/64 -j ACCEPT
#

And there is no problem

The manpage suggests that it should work:
d, --destination [!] address[/mask]
     Destination specification. See the description of the -s (source)
flag for a detailed description of the syntax. The flag --dst is an
alias for this option.


Am I doing something daft or should this work?

[toc] | [next] | [standalone]


#241090

FromMarkus Schönhaber <debian-user@list-post.mks-mail.de>
Date2021-10-10 14:30 +0200
Message-ID<D6G7L-4JL-3@gated-at.bofh.it>
In reply to#241084
10.10.21, 13:06 +0200, Tim Woodall:

> When I try to add the following rule:
> 
> # ip6tables -t nat -A POSTROUTING -s 2001::/64 -d ! 2001:1::/64 -j ACCEPT
> Bad argument `2001:1::/64'
> Try `ip6tables -h' or 'ip6tables --help' for more information.
> 
> It is rejected. (Ignore the fact that this rule doesn't make a huge
> amount of sense, it's a very cut down instance of the rule that I'm
> really trying to add)
> 
> Leaving off the exclusion:
> # ip6tables -t nat -A POSTROUTING -s 2001::/64 -d 2001:1::/64 -j ACCEPT
> #
> 
> And there is no problem
> 
> The manpage suggests that it should work:
> d, --destination [!] address[/mask]
>       Destination specification. See the description of the -s (source)
> flag for a detailed description of the syntax. The flag --dst is an
> alias for this option.

The man page I see on bullseye suggests otherwise:

>        [!] -d, --destination address[/mask][,...]
>               Destination  specification.   See the description of the -s (source) flag for a detailed description of the syntax.  The flag --dst is
>               an alias for this option.

i. e. putting The '!' left of the '-d' works:
# ip6tables -t nat -A POSTROUTING -s 2001::/64 ! -d 2001:1::/64 -j ACCEPT

Granted, the explanation in the man page for "!" under "--source" seems 
a bit ambiguous to me:

>        [!] -s, --source address[/mask][,...]
[...]
>               A "!"  argument before the address specification inverts the sense of the address.

The start of the paragraph shows where the "!" belongs, though.

-- 
Regards
   mks

[toc] | [prev] | [next] | [standalone]


#241091

FromReco <recoverym4n@enotuniq.net>
Date2021-10-10 14:40 +0200
Message-ID<D6Ghs-4MT-7@gated-at.bofh.it>
In reply to#241084
	Hi.

On Sun, Oct 10, 2021 at 12:06:25PM +0100, Tim Woodall wrote:
> When I try to add the following rule:
> 
> # ip6tables -t nat -A POSTROUTING -s 2001::/64 -d ! 2001:1::/64 -j ACCEPT
> Bad argument `2001:1::/64'
> Try `ip6tables -h' or 'ip6tables --help' for more information.
> 
> It is rejected.

As it should. This is correct one:

ip6tables -t nat -A POSTROUTING -s 2001::/64 ! -d 2001:1::/64 -j ACCEPT

It's a known quirk of iptables - you apply inversion *before* the test,
not *inside* of it.

> And there is no problem
> 
> The manpage suggests that it should work:
> d, --destination [!] address[/mask]

My instance of the same manpage states differently:

[!] -d, --destination address[/mask][,...]

But I'm using current stable, I'm unsure how this quirk was documented
before, but it behaved this was for two major Debian releases, maybe
more.

Reco

[toc] | [prev] | [next] | [standalone]


#241106

FromTim Woodall <debianuser@woodall.me.uk>
Date2021-10-10 18:30 +0200
Message-ID<D6JS1-6XL-3@gated-at.bofh.it>
In reply to#241091
On Sun, 10 Oct 2021, Reco wrote:

> On Sun, Oct 10, 2021 at 12:06:25PM +0100, Tim Woodall wrote:
>> When I try to add the following rule:
>>
>> # ip6tables -t nat -A POSTROUTING -s 2001::/64 -d ! 2001:1::/64 -j ACCEPT
>> Bad argument `2001:1::/64'
>> Try `ip6tables -h' or 'ip6tables --help' for more information.
>>
>> It is rejected.
>
> As it should. This is correct one:
>
> ip6tables -t nat -A POSTROUTING -s 2001::/64 ! -d 2001:1::/64 -j ACCEPT
>
> It's a known quirk of iptables - you apply inversion *before* the test,
> not *inside* of it.
>
>> And there is no problem
>>
>> The manpage suggests that it should work:
>> d, --destination [!] address[/mask]
>
> My instance of the same manpage states differently:
>
> [!] -d, --destination address[/mask][,...]
>
> But I'm using current stable, I'm unsure how this quirk was documented
> before, but it behaved this was for two major Debian releases, maybe
> more.
>

Thanks both! It's now working. And, indeed, my manpage does have it the
way you suggest. I'd initially found the documentation via a web search
and not twigged that the manpage and the documenatation here were
different:

https://linux.die.net/man/8/ip6tables

Tim.

[toc] | [prev] | [next] | [standalone]


#241160

FromAndrei POPESCU <andreimpopescu@gmail.com>
Date2021-10-11 11:00 +0200
Message-ID<D6Zk6-8wm-1@gated-at.bofh.it>
In reply to#241106

[Multipart message — attachments visible in raw view] — view raw

On Du, 10 oct 21, 17:19:52, Tim Woodall wrote:
> 
> Thanks both! It's now working. And, indeed, my manpage does have it the
> way you suggest. I'd initially found the documentation via a web search
> and not twigged that the manpage and the documenatation here were
> different:
> 
> https://linux.die.net/man/8/ip6tables

If you prefer reading manpages on the web you might want to use
https://manpages.debian.org. That way you are looking at the manpage 
corresponding to your specific software and version[1].

It can be also be added as an alternative search engine to most common 
browsers.

[1] Debian Developers patch manpages too occasionally, to document 
Debian specific changes, e.g. see the explanations for the -X and -Y 
switches in ssh(1).

Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web