netfilter-devel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* nftables in network name spaces breaks networking
@ 2014-10-29 12:00 Ed Tomlinson
  2014-11-17 19:37 ` Pablo Neira Ayuso
  0 siblings, 1 reply; 2+ messages in thread
From: Ed Tomlinson @ 2014-10-29 12:00 UTC (permalink / raw)
  To: netfilter-devel; +Cc: pablo

Hi

Using 3.17.1 and setting up firewalls with nftables breaks networking when nft -f <somefile> is run in an systemd-nspawn instance.  

Please take a look at: https://bugs.freedesktop.org/show_bug.cgi?id=85464 

The network gets setup correctly either by systemd-nspawn or manually via ip netns and all is okay until you try to load a firewall in
the spawned instance with nftables.  At this point the host's bridge interface stop responding.  Load a nftable in the spawned client 
should NOT affect the host's networking.

I like nftables and find them easier to use than iptables (or ipchains which dates me).

Please fix this problem or stop nft from loading tables when not it the root namespace.

I am willing to test fixes.

Thanks,
Ed Tomlinson


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2014-11-17 19:35 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-10-29 12:00 nftables in network name spaces breaks networking Ed Tomlinson
2014-11-17 19:37 ` Pablo Neira Ayuso

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).