All of lore.kernel.org
 help / color / mirror / Atom feed
* Incomprehensible behavior
@ 2023-08-03 14:43 toml
  2023-08-03 15:04 ` Florian Westphal
  0 siblings, 1 reply; 4+ messages in thread
From: toml @ 2023-08-03 14:43 UTC (permalink / raw)
  To: netfilter

(I'm so sorry... my previous post is in failed format... please ignore)

Hello @ all

I'm still struggling anymore with the new syntax at
ApplicationLayerGateway/FTP and testing with smallest steps. In doing
so I have now come across the following effect. I have 2 test-rules
here, both of which i expected to completely block any outgoing
traffic.

But as you can see from the second example in the counter, only here is
blocked. The first example has no effect at all, everything works as if
it was not blocked.

# nft list ruleset
table ip filter {
 chain output {
 type filter hook output priority 0; policy drop;
 meta pkttype { 0, 1, 2 } accept
 counter packets 0 bytes 0 reject with icmp 13
 }
}

# nft list ruleset
table ip filter {
 chain output {
 type filter hook output priority 0; policy drop;
 meta pkttype { 1, 2 } accept
 counter packets 1858 bytes 165434 reject with icmp 13
 }
}

Is this a desired behavior, when a unicast-accept virtually neutralizes
the complete filter? How do I deal with this problem?

Best Regards
Thomas


^ permalink raw reply	[flat|nested] 4+ messages in thread
* Incomprehensible behavior
@ 2023-08-03 14:37 toml
  0 siblings, 0 replies; 4+ messages in thread
From: toml @ 2023-08-03 14:37 UTC (permalink / raw)
  To: netfilter

Hello @ all

I'm still struggling anymore with the new syntax at ApplicationLayerGateway/FTP and testing with smallest steps. In doing so I have now come across the following effect. I have 2 test-rules here, both of which i expected to completely block any outgoing traffic.

But as you can see from the second example in the counter, only here is blocked. The first example has no effect at all, everything works as if it was not blocked.

# nft list ruleset
table ip filter {
    chain output {
        type filter hook output priority 0; policy drop;
        meta pkttype { 0, 1, 2 } accept
        counter packets 0 bytes 0 reject with icmp 13
    }
}

# nft list ruleset
table ip filter {
    chain output {
        type filter hook output priority 0; policy drop;
        meta pkttype { 1, 2 } accept
        counter packets 1858 bytes 165434 reject with icmp 13
    }
}

Is this a desired behavior, when a unicast-accept virtually neutralizes the complete filter? How do I deal with this problem?

Best Regards
Thomas

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2023-08-03 15:59 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-08-03 14:43 Incomprehensible behavior toml
2023-08-03 15:04 ` Florian Westphal
2023-08-03 15:59   ` toml
  -- strict thread matches above, loose matches on Subject: below --
2023-08-03 14:37 toml

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.