Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #265834
| From | Tom Furie <tom@furie.org.uk> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: nftables firewall question: matching udp in ipv6 |
| Date | 2024-01-12 17:00 +0100 |
| Message-ID | <HVs6R-2BLt-9@gated-at.bofh.it> (permalink) |
| References | <HVrNw-2BEZ-21@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Ralph Aichinger <ra@h5.or.at> writes:
> I am currently fighting with the following problem: I've got a system
> that has 3 relevant interfaces: ppp0, en0 and en2, for external,
> internal and dmz respectively.
>
> The dmz is IPv6 only, a homelab testbed more or less.
>
> I've got the follwing rules in /etc/nftables.conf for ipv6 (i am
> abreviating the chain input, because i am only fighting with
> forwarding):
>
> table ip6 filter {
> chain input {
> ...
> }
>
>
> chain forward {
> type filter hook forward priority 0; policy drop;
>
> iifname ppp0 oifname en0 ct state established,related accept
> iifname en0 oifname ppp0 accept
>
> iifname en2 oifname ppp0 accept
> iifname ppp0 oifname en2 accept
>
> iifname en0 oifname en2 accept
> iifname en2 oifname en0 ct state established,related accept
>
> meta l4proto ipv6-icmp accept
>
>
> }
> }
>
> What does not work, and this puzzles me, is that UDP does not work.
> E.g. if I lookup a DNS name in my dmz (connected to en2), I see no
> udp packets if i start tcpdump on the external interface ppp0. I see
> them entering on en2.
>
Where is the DNS server the dmz host is resolving against? In your dmz,
your internal network, on the firewall machine, outside? You may have
other input/output rules that are interfering, but since you've abridged
your ruleset we have no way of knowing.
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 16:40 +0100
Re: nftables firewall question: matching udp in ipv6 Tom Furie <tom@furie.org.uk> - 2024-01-12 17:00 +0100
Re: nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 17:30 +0100
Re: nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 17:40 +0100
Re: nftables firewall question: matching udp in ipv6 Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-01-12 18:30 +0100
Re: nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 19:10 +0100
Re: nftables firewall question: matching udp in ipv6 Michel Verdier <mv524@free.fr> - 2024-01-12 19:40 +0100
Re: nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 21:20 +0100
Re: nftables firewall question: matching udp in ipv6 Michel Verdier <mv524@free.fr> - 2024-01-12 22:10 +0100
csiph-web