Linux Netfilter development
 help / color / mirror / Atom feed
From: Phil Sutter <phil@nwl.cc>
To: "Serguei Bezverkhi (sbezverk)" <sbezverk@cisco.com>
Cc: Arturo Borrero Gonzalez <arturo@netfilter.org>,
	Pablo Neira Ayuso <pablo@netfilter.org>,
	Florian Westphal <fw@strlen.de>,
	"netfilter-devel@vger.kernel.org"
	<netfilter-devel@vger.kernel.org>,
	Laura Garcia <nevola@gmail.com>
Subject: Re: Operation not supported when adding jump command
Date: Thu, 28 Nov 2019 14:08:14 +0100	[thread overview]
Message-ID: <20191128130814.GQ8016@orbyte.nwl.cc> (raw)
In-Reply-To: <739A821F-2645-41B2-AADA-AA6C34A17335@cisco.com>

Hi Serguei,

On Thu, Nov 28, 2019 at 01:22:17AM +0000, Serguei Bezverkhi (sbezverk) wrote:
> Please see below the list of nftables rules the code generate to mimic only filter chain portion of kube proxy.
> 
> Here is the location of code programming these rules. 
> https://github.com/sbezverk/nftableslib-samples/blob/master/proxy/mimic-filter/mimic-filter.go
> 
> Most of rules are static, will be programed  just once when proxy comes up, with the exception is 2 rules in k8s-filter-services chain. The reference to the list of ports can change. Ideally it would be great to express these two rules with a single rule and a vmap, where the key must be service's ip AND service port, as it is possible to have a single service IP that can be associated with several ports and some of these ports might have an endpoint and some do not. So far I could not figure it out. Appreciate your thought/suggestions/critics. If you could file an issue for anything you feel needs to be discussed, that would be great.

What about something like this:

| table ip t {
| 	map m {
| 		type ipv4_addr . inet_service : verdict
| 		elements = { 192.168.80.104 . 8989 : goto do_reject }
| 	}
| 
| 	chain c {
| 		ip daddr . tcp dport vmap @m
| 	}
| 
| 	chain do_reject {
| 		reject with icmp type host-unreachable
| 	}
| }

For unknown reasons reject statement can't be used directly in a verdict
map, but the do_reject chain hack works.

> sudo nft list table ipv4table
> table ip ipv4table {
> 	set svc1-no-endpoints {
> 		type inet_service
> 		elements = { 8989 }
> 	}
> 
> 	chain filter-input {
> 		type filter hook input priority filter; policy accept;
> 		ct state new jump k8s-filter-services
> 		jump k8s-filter-firewall
> 	}
> 
> 	chain filter-output {
> 		type filter hook output priority filter; policy accept;
> 		ct state new jump k8s-filter-services
> 		jump k8s-filter-firewall
> 	}

Same ruleset for input and output? Seems weird given the daddr-based
filtering in k8s-filter-services.

Cheers, Phil

  parent reply	other threads:[~2019-11-28 13:08 UTC|newest]

Thread overview: 34+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2019-11-25 18:55 Operation not supported when adding jump command Serguei Bezverkhi (sbezverk)
2019-11-26 12:21 ` Florian Westphal
2019-11-26 14:30   ` Serguei Bezverkhi (sbezverk)
2019-11-26 14:52     ` Florian Westphal
2019-11-26 15:38     ` Pablo Neira Ayuso
2019-11-26 15:47       ` Serguei Bezverkhi (sbezverk)
2019-11-26 15:51         ` Phil Sutter
2019-11-26 18:47           ` Serguei Bezverkhi (sbezverk)
2019-11-26 19:27             ` Phil Sutter
2019-11-26 21:20               ` Serguei Bezverkhi (sbezverk)
2019-11-26 22:15                 ` Phil Sutter
2019-11-27 10:11                 ` Arturo Borrero Gonzalez
2019-11-27 11:57                   ` Phil Sutter
2019-11-27 14:36                   ` Serguei Bezverkhi (sbezverk)
2019-11-27 15:08                     ` Phil Sutter
2019-11-27 15:35                       ` Serguei Bezverkhi (sbezverk)
2019-11-27 16:06                         ` Phil Sutter
2019-11-27 16:50                           ` Serguei Bezverkhi (sbezverk)
2019-11-27 17:22                             ` Phil Sutter
2019-11-28  1:22                               ` Serguei Bezverkhi (sbezverk)
2019-11-28  9:10                                 ` Laura Garcia
2019-11-28 11:58                                   ` Serguei Bezverkhi (sbezverk)
2019-11-28 13:08                                 ` Phil Sutter [this message]
2019-11-28 13:34                                   ` Serguei Bezverkhi (sbezverk)
2019-11-28 14:51                                   ` Serguei Bezverkhi (sbezverk)
2019-11-28 15:15                                     ` Phil Sutter
2019-11-29 20:13                                       ` Serguei Bezverkhi (sbezverk)
2019-11-30  0:04                                         ` Phil Sutter
2019-12-03 18:43                                           ` Serguei Bezverkhi (sbezverk)
2019-12-04 10:36                                             ` Phil Sutter
2019-12-03 23:50 ` Duncan Roe
2019-12-04  1:13   ` [PATCH nft] doc: Clarify conditions under which a reject verdict is permissible Duncan Roe
2019-12-06  2:37   ` [PATCH nft v2] " Duncan Roe
2019-12-06  6:55     ` Florian Westphal

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20191128130814.GQ8016@orbyte.nwl.cc \
    --to=phil@nwl.cc \
    --cc=arturo@netfilter.org \
    --cc=fw@strlen.de \
    --cc=netfilter-devel@vger.kernel.org \
    --cc=nevola@gmail.com \
    --cc=pablo@netfilter.org \
    --cc=sbezverk@cisco.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox