Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #265840

Re: nftables firewall question: matching udp in ipv6

From Ralph Aichinger <ra@h5.or.at>
Newsgroups linux.debian.user
Subject Re: nftables firewall question: matching udp in ipv6
Date 2024-01-12 17:40 +0100
Message-ID <HVsJz-2CdQ-7@gated-at.bofh.it> (permalink)
References <HVrNw-2BEZ-21@gated-at.bofh.it> <HVs6R-2BLt-9@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Fri, Jan 12, 2024 at 03:52:46PM +0000, Tom Furie wrote:
> other input/output rules that are interfering, but since you've abridged
> your ruleset we have no way of knowing.

Sorry, wanted to include the full rulest an forgot. I've still have left
off the "table ip nat" and "table ip filter" chains, I hope this is OK.


#!/usr/sbin/nft -f

flush ruleset

table ip nat {
...
}

table ip filter {
...
}

table ip6 filter {
        chain input {
                type filter hook input priority 0; policy drop;
                ct state invalid counter drop comment "early drop of invalid packets"
                ct state {established, related} counter accept comment "accept all connections related to connections made by us"
                iif lo accept comment "accept loopback"
                iif != lo ip6 daddr ::1/128 counter drop comment "drop connections to loopback not coming from loopback"
                meta l4proto ipv6-icmp counter accept comment "accept all ICMP types"
                tcp dport 22 counter accept comment "accept SSH"
                tcp dport 25 counter accept comment "accept SMTP"
                tcp dport 53 counter accept comment "accept DNS"
                udp dport 53 counter accept comment "accept DNS"
                tcp dport 80 counter accept comment "accept HTTP"
                tcp dport 443 counter accept comment "accept HTTPS"
                counter comment "count dropped packets"
        }

        
        chain forward {
                type filter hook forward priority 0; policy drop;

                iifname ppp0 oifname en0 ct state established,related accept
                iifname en0 oifname ppp0 accept
                                        
                iifname en2 oifname ppp0 accept
                iifname ppp0 oifname en2 accept

                iifname en0 oifname en2 accept
                iifname en2 oifname en0 ct state established,related accept

                meta l4proto ipv6-icmp accept

        }
}

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 16:40 +0100
  Re: nftables firewall question: matching udp in ipv6 Tom Furie <tom@furie.org.uk> - 2024-01-12 17:00 +0100
    Re: nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 17:30 +0100
    Re: nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 17:40 +0100
  Re: nftables firewall question: matching udp in ipv6 Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-01-12 18:30 +0100
    Re: nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 19:10 +0100
  Re: nftables firewall question: matching udp in ipv6 Michel Verdier <mv524@free.fr> - 2024-01-12 19:40 +0100
    Re: nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 21:20 +0100
      Re: nftables firewall question: matching udp in ipv6 Michel Verdier <mv524@free.fr> - 2024-01-12 22:10 +0100

csiph-web