Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #265843

Re: nftables firewall question: matching udp in ipv6

From Michael Kjörling <2695bd53d63c@ewoof.net>
Newsgroups linux.debian.user
Subject Re: nftables firewall question: matching udp in ipv6
Date 2024-01-12 18:30 +0100
Message-ID <HVtvX-2CJe-5@gated-at.bofh.it> (permalink)
References <HVrNw-2BEZ-21@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On 12 Jan 2024 16:19 +0100, from ra@h5.or.at (Ralph Aichinger):
> If I insert the following rule at the bottom, everything starts to
> work:
> 
> meta l4proto  udp  accept
> 
> but I don't know how to limit this over broad rule (so it does not
> forward UDP to the internal network on en0, which I do not want). 

My suggestion would be to insert a "udp log" rule. (Pretty sure you
only need "udp", not "meta l4proto udp".)

That will give you a firehose of information which will include ports,
interfaces and other relevant information. You can then narrow it down
until it logs the traffic you want to accept, at which point you can
change the "log" action into an "accept" action.

Note that forwarding and filtering can interact in non-intuitive ways.
You may need to add corresponding log rules to each relevant chain,
maybe with a prefix to tell them apart.

-- 
Michael Kjörling                     🔗 https://michael.kjorling.se
“Remember when, on the Internet, nobody cared that you were a dog?”

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 16:40 +0100
  Re: nftables firewall question: matching udp in ipv6 Tom Furie <tom@furie.org.uk> - 2024-01-12 17:00 +0100
    Re: nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 17:30 +0100
    Re: nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 17:40 +0100
  Re: nftables firewall question: matching udp in ipv6 Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-01-12 18:30 +0100
    Re: nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 19:10 +0100
  Re: nftables firewall question: matching udp in ipv6 Michel Verdier <mv524@free.fr> - 2024-01-12 19:40 +0100
    Re: nftables firewall question: matching udp in ipv6 Ralph Aichinger <ra@h5.or.at> - 2024-01-12 21:20 +0100
      Re: nftables firewall question: matching udp in ipv6 Michel Verdier <mv524@free.fr> - 2024-01-12 22:10 +0100

csiph-web