Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #228502
| From | Jesper Dybdal <jd-debian-user@dybdal.dk> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: Stretch => Buster: iptables |
| Date | 2020-11-06 12:10 +0100 |
| Message-ID | <B87N0-1gP-29@gated-at.bofh.it> (permalink) |
| References | <B0v9L-4bV-1@gated-at.bofh.it> <B86xA-lp-1@gated-at.bofh.it> <B87tE-UE-5@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
[Multipart message — attachments visible in raw view] - view raw
On 2020-11-06 11:43, Sven Hartge wrote:
> Jesper Dybdal <jd-debian-user@dybdal.dk> wrote:
>> * The CT target, to add the ftp helper. I fixed that by adding a bit of
>> native nft with the nft command after all the iptables(-nft) commands.
> For the sake of the archive and people looking at this thread hoping for
> some insight, please post your native nft rules you created.
Here they are (I'm afraid I can't remember which websites I got the
inspiration from):
table ip myhelpers {
ct helper ftp-standard {
type "ftp" protocol tcp
}
chain input {
type filter hook prerouting priority 0;
tcp dport 21 ct helper set "ftp-standard" counter
}
chain output {
type filter hook output priority 0;
tcp dport 21 ct helper set "ftp-standard" counter
}
}
I loaded them after all the iptables-nft rules with the commands:
# Delete any existing myhelpers tables, ignoring possible failure for an
non-existent table:
nft delete table myhelpers >/dev/null 2>&1
# Load the myhelpers table shown above:
nft -f myhelpers.nft
This seems to work.
--
Jesper Dybdal
https://www.dybdal.dk
Back to linux.debian.user | Previous | Next — Previous in thread | Find similar | Unroll thread
Stretch => Buster: iptables Jesper Dybdal <jd-debian-user@dybdal.dk> - 2020-10-16 12:30 +0200
Re: Stretch => Buster: iptables Reco <recoverym4n@enotuniq.net> - 2020-10-16 12:40 +0200
Re: Stretch => Buster: iptables Jesper Dybdal <jd-debian-user@dybdal.dk> - 2020-10-16 14:20 +0200
Re: Stretch => Buster: iptables Pierre-Elliott Bécue <peb@debian.org> - 2020-10-16 16:30 +0200
Re: Stretch => Buster: iptables Jesper Dybdal <jd-debian-user@dybdal.dk> - 2020-11-06 10:50 +0100
Re: Stretch => Buster: iptables Sven Hartge <sven@svenhartge.de> - 2020-11-06 11:50 +0100
Re: Stretch => Buster: iptables Jesper Dybdal <jd-debian-user@dybdal.dk> - 2020-11-06 12:10 +0100
csiph-web