public inbox for netfilter@vger.kernel.org
 help / color / mirror / Atom feed
* Nftables ct count over 2 counter continues to trigger with only 1 connection
@ 2025-10-22 22:54 louis.t42
  2025-10-23 11:42 ` Pablo Neira Ayuso
                   ` (2 more replies)
  0 siblings, 3 replies; 6+ messages in thread
From: louis.t42 @ 2025-10-22 22:54 UTC (permalink / raw)
  To: netfilter

Hello,

I have read the documentation and asked on Stack Exchange but am unable to find an answer to the following behavior.

Given this table and chain where 123.123.123.123 is my own address:

table ip mytable {
        chain mychain {
                type filter hook input priority filter; policy accept;
                ip saddr != 123.123.123.123 drop
                ip saddr 123.123.123.123 ct count over 2 counter
        }
}

I am establishing a varying number of TCP connections from my own address by connecting via SSH. These show up in "ss -at" and "conntrack -L" as well as disappear once disconnected - all as expected.

With 2 connections open I see "packets 0 bytes 0" on the counter. With 3 connections open I see "packets 6599 bytes 475441".

The question: when disconnecting 2 of the connections (from 3 total back to 1 total) the counter continues to increment. It triggers even when "ss -at" and "conntrack -L" show just one connection with no TIME_WAIT or other entries.

It even continues incrementing after a "conntrack -F" and often feels as though it is a one-way switch once the counter has triggered. Sometimes closing all connections (to 0 total) stops the counter from incrementing.

Is there an explanation as to this "ct count" behavior in more detail?

Thanks.

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2025-10-27 22:25 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-10-22 22:54 Nftables ct count over 2 counter continues to trigger with only 1 connection louis.t42
2025-10-23 11:42 ` Pablo Neira Ayuso
2025-10-23 14:00 ` Fernando Fernandez Mancera
2025-10-24 11:45 ` Florian Westphal
2025-10-27 13:54   ` louis.t42
2025-10-27 22:25     ` Pablo Neira Ayuso

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox