Re: NFULNL_CFG_F_CONNTRACK and IPv6

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



> > log received (prefix="TRACE: raw:OUTPUT:policy:3 " hw=0x86dd hook=3 mark=0)
> > <log><when><hour>2</hour><min>05</min><sec>01</sec><wday>4</wday><day>13</day><month>1</month><year>2021</year></when><prefix>TRACE: raw:OUTPUT:policy:3 </prefix><hook>3</hook><hw><proto>86dd</proto></hw><outdev>12</outdev></log> (ret=229)
> > log received (prefix="TRACE: raw:OUTPUT:policy:3 " hw=0x86dd hook=3 mark=0)
> > <log><when><hour>2</hour><min>05</min><sec>01</sec><wday>4</wday><day>13</day><month>1</month><year>2021</year></when><prefix>TRACE: raw:OUTPUT:policy:3 </prefix><hook>3</hook><hw><proto>86dd</proto></hw><outdev>12</outdev></log> (ret=229)
> > log received (prefix="TRACE: raw:OUTPUT:policy:3 " hw=0x86dd hook=3 mark=0)
> > <log><when><hour>2</hour><min>05</min><sec>01</sec><wday>4</wday><day>13</day><month>1</month><year>2021</year></when><prefix>TRACE: raw:OUTPUT:policy:3 </prefix><hook>3</hook><hw><proto>86dd</proto></hw><outdev>12</outdev></log> (ret=229)
> 
> There is no conntrack information yet in the raw table.

Yep, that was it. I had a IPv4 nat rule that made conntrack to confuse me and appear as an intermittent trace for the raw table conntrack rule. Had nothing for ipv6 so that is why IPv6 seemed not to work at all. 

Got it:

  tcp      6 432000 ESTABLISHED src=fe80::472:eeff:fef8:dbb6 dst=fe80::5054:ff:fecc:767d sport=53866 dport=22 src=fe80::5054:ff:fecc:767d dst=fe80::472:eeff:fef8:dbb6 sport=22 dport=53866 [ASSURED]
log received (prefix="TRACE: mangle:POSTROUTING:policy:1 " hw=0x86dd hook=4 mark=0)
<log><when><hour>18</hour><min>05</min><sec>27</sec><wday>4</wday><day>13</day><month>1</month><year>2021</year></when><prefix>TRACE: mangle:POSTROUTING:policy:1 </prefix><hook>4</hook><hw><proto>86dd</proto></hw><outdev>12</outdev></log> (ret=238)

Thanks a lot Pablo!



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux