All of lore.kernel.org
 help / color / mirror / Atom feed
From: Pablo Neira Ayuso <pablo@netfilter.org>
To: Volodymyr Litovka <doka@funlab.cc>
Cc: netfilter@vger.kernel.org
Subject: Re: nftables / DHCP / NAT
Date: Mon, 30 Oct 2023 09:41:37 +0100	[thread overview]
Message-ID: <ZT9sQZw2hmkM5nh2@calendula> (raw)
In-Reply-To: <df94652d-d611-4713-963a-911d6b7ef986@funlab.cc>

On Fri, Oct 27, 2023 at 06:32:45PM +0200, Volodymyr Litovka wrote:
> The question - what I'm doing wrong?

Description, ruleset and topology look a bit convoluted :-)

To start with:

        iifname "inspan" ...

is not really required, because you chain is already hooked at
"inspan" device see your chain declaration:

table netdev inspan {
    chain rewrit {
        # Drop everything except Radius Accounting and DHCP packets
        type filter hook ingress device "inspan" priority filter; policy drop;

Then, to forward packets to some other box from the 'netdev' family,
use the 'fwd' statement:

        udp dport 67 udp dport set 10067 counter fwd to 100.64.0.66 device "eth0"

This rule above is mangling your UDP destination port from 67 to
10067, then it send the packet to 100.64.0.66 and device "eth0". The
destination MAC address is updated by the neighbour layer so you do
not have to bother with "ether daddr set ...".

       reply	other threads:[~2023-10-30  8:41 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <df94652d-d611-4713-963a-911d6b7ef986@funlab.cc>
2023-10-30  8:41 ` Pablo Neira Ayuso [this message]
2023-10-30 11:58   ` nftables / DHCP / NAT Volodymyr Litovka
     [not found]   ` <54fda956-92bd-4c14-b0e5-29445b53f04a@funlab.cc>
2023-10-30 16:40     ` Pablo Neira Ayuso
2023-10-30 22:20   ` Volodymyr Litovka
2023-10-31 14:05     ` Pablo Neira Ayuso
2023-10-31 21:26       ` Volodymyr Litovka

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ZT9sQZw2hmkM5nh2@calendula \
    --to=pablo@netfilter.org \
    --cc=doka@funlab.cc \
    --cc=netfilter@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.