Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #265843
| From | Michael Kjörling <2695bd53d63c@ewoof.net> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: nftables firewall question: matching udp in ipv6 |
| Date | 2024-01-12 18:30 +0100 |
| Message-ID | <HVtvX-2CJe-5@gated-at.bofh.it> (permalink) |
| References | <HVrNw-2BEZ-21@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On 12 Jan 2024 16:19 +0100, from ra@h5.or.at (Ralph Aichinger): > If I insert the following rule at the bottom, everything starts to > work: > > meta l4proto udp accept > > but I don't know how to limit this over broad rule (so it does not > forward UDP to the internal network on en0, which I do not want). My suggestion would be to insert a "udp log" rule. (Pretty sure you only need "udp", not "meta l4proto udp".) That will give you a firehose of information which will include ports, interfaces and other relevant information. You can then narrow it down until it logs the traffic you want to accept, at which point you can change the "log" action into an "accept" action. Note that forwarding and filtering can interact in non-intuitive ways. You may need to add corresponding log rules to each relevant chain, maybe with a prefix to tell them apart. -- Michael Kjörling 🔗 https://michael.kjorling.se “Remember when, on the Internet, nobody cared that you were a dog?”
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 16:40 +0100
Re: nftables firewall question: matching udp in ipv6 Tom Furie <tom@furie.org.uk> - 2024-01-12 17:00 +0100
Re: nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 17:30 +0100
Re: nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 17:40 +0100
Re: nftables firewall question: matching udp in ipv6 Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-01-12 18:30 +0100
Re: nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 19:10 +0100
Re: nftables firewall question: matching udp in ipv6 Michel Verdier <mv524@free.fr> - 2024-01-12 19:40 +0100
Re: nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 21:20 +0100
Re: nftables firewall question: matching udp in ipv6 Michel Verdier <mv524@free.fr> - 2024-01-12 22:10 +0100
csiph-web