Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #228503
| From | Jesper Dybdal <jd-debian@dybdal.dk> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | nftable questions |
| Date | 2020-11-06 12:20 +0100 |
| Message-ID | <B87WG-1ko-7@gated-at.bofh.it> (permalink) |
| Organization | linux.* mail to news gateway |
I'm beginning to plan the transition from iptables-nft to native nftables. I plan to have a shell script that builds a set of "define" statements and concatenates then with the actual nft script that uses them. Question 1: What is the difference between "meta l4proto tcp tcp dport 22" and just "tcp dport 22". I've seen examples of both, and both seem to work. Question 2: Is there a way to specify conditional inclusion of rules in a file loaded with "nft -f"? I.e., something like: define AllowSsh = 1 # or 0 ... if AllowSsh meta l4proto tcp tcp dport 22 accept else meta l4proto tcp tcp dport 22 drop endif ? Thanks, Jesper -- Jesper Dybdal https://www.dybdal.dk
Back to linux.debian.user | Previous | Next | Find similar | Unroll thread
nftable questions Jesper Dybdal <jd-debian@dybdal.dk> - 2020-11-06 12:20 +0100
csiph-web