Linux Netfilter development
 help / color / mirror / Atom feed
* [nft PATCH] doc: nft.8: Document lower priority limit for nat type chains
@ 2023-03-09 13:52 Phil Sutter
  2023-03-09 15:23 ` Pablo Neira Ayuso
  2023-03-10 11:46 ` Phil Sutter
  0 siblings, 2 replies; 5+ messages in thread
From: Phil Sutter @ 2023-03-09 13:52 UTC (permalink / raw)
  To: Pablo Neira Ayuso; +Cc: netfilter-devel

Users can't know the magic limit.

Signed-off-by: Phil Sutter <phil@nwl.cc>
---
 doc/nft.txt | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/doc/nft.txt b/doc/nft.txt
index 7de4935b4b375..0d60c7520d31e 100644
--- a/doc/nft.txt
+++ b/doc/nft.txt
@@ -439,6 +439,9 @@ name which specifies the order in which chains with the same *hook* value are
 traversed. The ordering is ascending, i.e. lower priority values have precedence
 over higher ones.
 
+With *nat* type chains, there's a lower excluding limit of -200 for *priority*
+values, because conntrack hooks at this priority and NAT requires it.
+
 Standard priority values can be replaced with easily memorizable names.  Not all
 names make sense in every family with every hook (see the compatibility matrices
 below) but their numerical value can still be used for prioritizing chains.
-- 
2.38.0


^ permalink raw reply related	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2023-03-10 11:46 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-03-09 13:52 [nft PATCH] doc: nft.8: Document lower priority limit for nat type chains Phil Sutter
2023-03-09 15:23 ` Pablo Neira Ayuso
2023-03-09 15:32   ` Phil Sutter
2023-03-09 17:34     ` Pablo Neira Ayuso
2023-03-10 11:46 ` Phil Sutter

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox