Questions tagged [nftables]
nftables is the successor of iptables/ip6tables and available since Linux kernel version 3.13
275 questions
0 votes
0 answers
36 views
firewalld corruption python-nftables command not found
this is in RHEL-8.10 x86-64 from a clean install from rhel-8.10-x86_64-dvd.iso and only using the public.xml file; the only things I do is # quad port nic with eno4 being my wan connection firewall-...
0 votes
0 answers
38 views
Problem using "dynamic" maps with nftables
I want to create an nftables filter rule that drops traffic where the source and destination address are equal. Nftables only allows to compare addresses against constants or sets/maps. So I tried to ...
1 vote
1 answer
61 views
Discrepancy in nftables counters
Here is an edited nft ruleset that shows what appears to be a problem with the values in the packet counters. In the INPUT chain, the second rule counter shows more packets than the first rule counter....
1 vote
2 answers
88 views
nftables anonymous subchains
Using ferm (the iptables generator) I can make anonymous chains like this: saddr (1.2.3.4 2.3.4.5 3.4.5.6 4.5.6.7 5.6.7.8) @subchain { proto tcp dport (http https ssh) ACCEPT; proto udp dport ...
1 vote
0 answers
42 views
What does the phrase "consider native interface" refer to when the nftables wiki says that xt_bpf match is unsupported
In this list of unsupported xtables features. xt_bpf is listed as one of the unsupported features. The comment says to "consider native interface". But what interface is being referred to ...
0 votes
1 answer
94 views
Misdocumentation in nftables?
As someone who hasn't hammered in all the parts of the OSI layers, I got quite frustrated with the documentation of bridge filtering in nftables: https://wiki.nftables.org/wiki-nftables/index.php/...
0 votes
0 answers
108 views
NFTables tables, hooks and rules ordering
I'm new to nftables but have used iptables for quite a while now. While playing with nftables, I was thinking: "Hey, this is cool, I could have like a management table, where all the mngt stuff ...
1 vote
0 answers
773 views
nft rules added to table inet filter do not work
I am running a Ubuntu Server and I am trying to allow some traffic to pass from one interface to another. The server is configured to route traffic, this is the topology: 172.16.0.0/12 --- ...