Re: [nftables 0.9.2 | kernel 4.19.93] dropping ct state untracked stops ipv6 connectivity

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



ѽ҉ᶬḳ℠ <vtol@xxxxxxx> wrote:
> That is one protocol (icmpv6 neigh resolution) being untracked but that
> implies that NFT is then subsequently blocking the source ipv6 entirely?

Its the same effect as dropping ipv4 arp packets with arptables,
stack won't be able to figure out which ethernet address to use to send
the packet to.



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux