Williams, Gareth <gareth@xxxxxxxxxxxxxxxxxxxx> wrote: > ip protocol udp reject with type port-unreachable > > netfilter seems to simply drop the packet. It should also send the icmp response. > back, which is an ICMP port unreachable message. I just can't seem to > get nftables to do the same. Kernel version? It works for me on 4.17. -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html