Linux Netfilter / IP Tables
[Prev Page][Next Page]
- Re: Failing to construct a 'set' for TCP Flag filtering., (continued)
- Nftables rules change when network interfaces disappear,
Mikhail Morfikov
- netfilter_queue tutorial,
Tomasz W
- inserting rule at the top of the chain using libnftnl, JM
- integrating netfilter_queue, Tomasz W
- nftables destination ip rewrite - checksum recalculation,
Greenberg, Paul
- Nftables src NAT with port range allocation,
Joshua Moore
- nftables map with numgen type, not sure if it was implemented?,
Eliezer Croitor
- How deactivate a rule using nft cli?,
Luis Mario Niedas Hernández
- Multiple labels with connlabel,
Amiq Nahas
- Load Balancing WAN connections with nftables, Eliezer Croitor
- Explanation of 2 Rules,
Thomas Luening
- Use ipset and conntrack with nftables,
Amiq Nahas
- Issue migrating "iptables -m socket --transparent" into nftables,
Nirgal Vourgère
Grammar in a bash script,
Mario V Guenzi
error using variable for network device name in 'hook ingress device $external_interface',
Grant C
50k rules and performance issue in nft list table AND iptables-nft,
Ricardo Katz
Nftables 2 WAN,
Daniel
Is it possible to change a chains default policy when rules are already present?,
Andreas Hoefler
ingress hook on interface with multiple addresses ?,
sean darcy
Correct syntax for dnat in inet table?,
Frank-Ulrich Sommer
nft arp, Dennis G
iptables: Log dropped packages due to missing ports when using masquerading,
Janosch Maier
usings sets as input to sets,
harald
iptables by cgroup path no longer works after starting Docker or KVM, Outvi V
No packets appear in ulogd.log, Austin Chamberlin
not able to set ct state rule,
Andreas Hoefler
Raw table on NFT, Cristian Cardoso
sets must have more than 2 elements , and can't "include" a set, sean darcy
Plan B on BCP-38 implementation in NFTABLES, Stephen Satchell
nftables: masquerading not applied consistently,
Thilo-Alexander Ginkel
nftables: Set Elements Listing: One Per Line, Mike Dillinger
nftables: Counters Not Working with Sets of Type Interval,
Mike Dillinger
iptables-nft and unsused default chains, Reindl Harald
IP masquerading not applied in TCP retransmission packets,
Aleksander Morgado
iptables-nft replacement for /proc/net/ip_tables_names,
Reindl Harald
libnftnl vlan type filter,
Andreas Hoefler
Moving from ipset to nftables: Sets not ready for prime time yet?,
Timo Sigurdsson
Filter source IP with UDP/514 destination port and change to UDP/9000,
Roberto Carna
iptables hashlimit scrip and srcport, jamez
callback on adding tables from mnl_cb_run for nftables,
Andreas Hoefler
[nft | wiki] List of updates since Linux kernel 3.13,
ѽ҉ᶬḳ℠
[nft 0.9.3 | kernel 5.4.48] cannot get NAT to work,
ѽ҉ᶬḳ℠
"Operation not supported" when using ct mark, Adam Degenhardt
Address List, Mario Vittorio Guenzi
nftables and connection tracking,
Marek Greško
Re: nftables and connection tracking, Pablo Neira Ayuso
ipsec matching in postrouting nat,
Marek Greško
WiFi Hotspot Disable Neighbor discovery,Ask,
Hooman
[ANNOUNCE] nftables 0.9.6 release, Pablo Neira Ayuso
loadbalance 2 internet links, paulo bruck
nftables drops related traffic,
Robin Kuiper
[ANNOUNCE] libnetfilter_queue 1.0.5 release, Florian Westphal
Looking to contribute to the nftables wiki, Gaelan Lloyd
Documentation.,
G.W. Haywood
[ANNOUNCE] nftables 0.9.5 release, Pablo Neira Ayuso
"Carrier Grade" NAT44 setup,
Maximilian Wilhelm
[ANNOUNCE] libnftnl 1.1.7 release, Pablo Neira Ayuso
[ANNOUNCE] libnetfilter_queue 1.0.4 release, Florian Westphal
Simplifying DNAT Rules using Maps,
Max Ehrlich
[ANNOUNCE] iptables 1.8.5 release, Phil Sutter
[MAINTENANCE] Shutting down FTP services at netfilter.org,
Pablo Neira Ayuso
Expressive limitation: (daddr,dport) <--> (daddr',dport'), Rick van Rein
Value too large for defined data type, ad^2
Let me make sure I have this right (fib),
Stephen Satchell
nft filter cgroup, Christian Schneider
Raw Expression for DNS name?,
ad^2
iif versus meta fib iif,
Stephen Satchell
WTF, over,
Stephen Satchell
Is this a correct usage of the FIB facility of NFTABLES? (BCP-38), Stephen Satchell
FIB filtering (comments, please) (reformatted), Stephen Satchell
FIB filtering (comments, please), Stephen Satchell
Timestamps, NFLOG, and ULOG,
Korodev
Fwd: Raw Expression matching DNS Query?, ad^2
nftables: defining variables containing ipv6 adresses,
Thomas Weberstaedt
saddr, daddr type determination, Stephen Satchell
Systemd, nftables, and iptables,
Stephen Satchell
- Re: Systemd, nftables, and iptables,
- Re: Systemd, nftables, and iptables, Reindl Harald
- Re: Systemd, nftables, and iptables, Alexander Dahl
- Re: Systemd, nftables, and iptables, Trent W. Buck
Netdev conf 0x14 update, Jamal Hadi Salim
Dynamic list for net's,
Іван Щербей
POSTROUTING doesn't apply on all outgoing packets, Walter Laub
-m statistic does not work with 5.6.8, Reindl Harald
nftables NAT & Gaming Consoles,
Mike Dillinger
nftables: Strange Error When Adding Element to Named Set,
Mike Dillinger
Correct usage of nf_ct_get,
b38911 Zxc
Firewall sometimes leaking,
Nick
[Help] Allow website using iptables,
Sơn Đỗ
Using the fib to classify endpoints., Stephen Satchell
Documentation Error on http://wiki.nftables.org/wiki-nftables/index.php/GeoIP_matching,
Bob and Sally Public
idempotent nft delete table? (or: why does "flush table" delete rules but keep chains?),
Trent W. Buck
cannot create a nat type base (pre/post routing) chain,
Norbert van Bolhuis
Multicast routed packets do not get SNAT translation performed, Stephen Deiters
Questions around the use of timestamps, Nikolaos Kakouros
nftables and traffic control utility to QoS,
d.gubin
conntrack traffic statistics and connlabel, Fatih USTA
has somebody an idea what fills up the log (5050/udp)?,
Walter H.
possible error in HOWTO, Fred Maranhão
ARP confirmed timestamp update on TCP data flow vs keep-alive, Steffen Heil (Mailinglisten)
[PATCH v1 1/1] Update download script for DBIP database, Philip Prindeville
[PATCH v1 1/1] update MaxMind URL's, Philip Prindeville
Is viewing a "candidate" ruleset in 'nft list ruleset' format possible?,
Martin Gignac
query re dynamic set and limiting,
James Bond
WARNING: at net/sched/sch_generic.c - Reproducible crash & rcu stalls, Christopher S. Aker
marking/routing packets breaks the conntrack rule for NAT, Mickael Bosch
Hello, I have some questions about flowtable., James Bond
validate IPsec outgoing packets using NFtables,
Olivier Alabeatrix
extending element timeout,
Alvaro Leiva
[ANNOUNCE] conntrack-tools 1.4.6, Pablo Neira Ayuso
[ANNOUNCE] libnetfilter_conntrack 1.0.8 release, Pablo Neira Ayuso
[ANNOUNCE] libnftnl 1.1.6 release, Pablo Neira Ayuso
[ANNOUNCE] nftables 0.9.4 release,
Pablo Neira Ayuso
[ANNOUNCE] nftlb 0.6 release,
Laura Garcia
netem qdisc destroys traffic in other tc classes (HFSC classes), kaskada
batch update of conntrack?, kaskada
Re: What is the BEST GUI frontend to iptables firewall?,
ѽ҉ᶬḳ℠
Re: What is the BEST GUI frontend to iptables firewall?, Daniel
Re: What is the BEST GUI frontend to iptables firewall?, Eric Garver
[libnftnl] documentation?,
ѽ҉ᶬḳ℠
A question about priority in chains,
darius
Ipv6tov4 address Dnat,
Zheng konia
tc question about ingress bandwidth splitting,
Philip Prindeville
[nftables 0.9.2 | flow table] check whether it works?,
ѽ҉ᶬḳ℠
TCP and UDP dport in the same rule,
Darius
[nftables 0.9.2 | flow table] dynamic (soft) NETDEV,
ѽ҉ᶬḳ℠
nftables 0.9.3, sets with concatentation,
Stefan Hartmann
Interface group ID in flow tables?, Robert White
Boundary Flag for "site" (IPv6) [Kernel Change?], Robert White
[nftables 0.9.2] NETDEV packet drop vs. packet capture visibility,
ѽ҉ᶬḳ℠
Advantage(s) of static over dynamic nftables sets?,
Frank Myhr
[nftables 0.9.2 | kernel 4.19.93] flowtable throws error on deployment (not on check however),
ѽ҉ᶬḳ℠
[nftables 0.9.2 | kernel 4.19.93] flowtable - number of devices limited (7)?,
ѽ҉ᶬḳ℠
[nftables 0.9.2 | kernel 4.19.93] dropping ct state untracked stops ipv6 connectivity,
ѽ҉ᶬḳ℠
Re: use libiptc to build a rule to allow tftp traffic,
Moyuan Chen
Restoring rulesets containing dynamic sets with counters,
Frank Myhr
nftables equivalent of "ipset test"?,
Frank Myhr
nft ingress won't work on wireless ?,
sean darcy
Set timeout, gc-interval and size parameters, Frank Myhr
use numgen to create address in rule,
Dennett Ingram
Found extra tables in nft ruleset,
Lars Noodén
Why inet table doesn't support nat prerouting chain?,
Glen Huang
LXD Container can't access trough host address, Franz Schneider
Is it possible to get a transparent proxy with Redsocks when using the new nftables?,
Verachten Bruno
nftables offload doesn't seem to work,
Patrick McLean
Demystifying sets,
jon_netfilter
wiki acess, pauloric
loadbalance with 2 or more links,
pauloric
[ANNOUNCE] ipset 7.6 released, Jozsef Kadlecsik
Typo in the 'Mangle TCP options' wiki pages, Pieter van Leuven
Waiting until first release of NFTABLES,
Stephen Satchell
Automatically maintaining unique list of addresses,
Lars Noodén
NFQUEUE/iptables and kernel warning messages for net/ipv4/tcp_output.c,
Vieri Di Paola
Resetting SKB CT, Mathew Heard
Problems with CONNTRACK --restore-mark, Bernd Jerzyna
Difficulties with ulog / NFCT,
Alessandro Vesely
nfnetlink: This library is not meant as a public API for application developers.,
Alessandro Vesely
[nftables 0.9.2] does jump require a kconf to be set to get it working?,
ѽ҉ᶬḳ℠
iptables MASQUERADE considering route source hints, Max Stritzinger
Does anybody experience kernel crush when 'ebtable -t nat -L',
양유석
Compiling nftables with stack-protector-strong fails checksec's canary check,
Glen Huang
[nftables] economics of reverse path filtering - FIB expression vs. kernel parameter,
ѽ҉ᶬḳ℠
nftables "native interface" for IPv6 NPT?,
Haochen Tong
Netfilter state synchronisation in IPv6 only networks?, Nico Schottelius
[firewall context] packet presentation for dual WAN interfaces on the same link - eth <> pppoe?,
ѽ҉ᶬḳ℠
Metering is not working with dynamic sets on nft v0.9.2,
darius
[nftables] inherent benefits from XDP?, ѽ҉ᶬḳ℠
[nftables] xtables-addons - GeoIP/ASN filter and lscan replicable?,
ѽ҉ᶬḳ℠
[nftables v0.9.2 | kernel 4.19.93] does redirect accept daddr?,
ѽ҉ᶬḳ℠
Redirect bridged traffic,
Jaga Doe
[nftables v0.9.2 | kernel 4.19.93] logging protocols in inet family table require explicit protocol statement?,
ѽ҉ᶬḳ℠
[nftables v0.9.2] inet <> ip | ip6 family tables processing order?,
ѽ҉ᶬḳ℠
[nftables v0.9.2 | kernel 4.19.93] MSS clamping rule possible in the inet family table?,
ѽ҉ᶬḳ℠
nftables simple configuration, Jaga Doe
nftables routing decision,
Иванов Роман
[nftables v0.9.2 | kernel 4.19.93] ICMPv6 ingress dropped despite accept rule,
ѽ҉ᶬḳ℠
Re: [nftables v0.9.2 | kernel 4.19.93] ICMPv6 ingress dropped despite accept rule, Duncan Roe
Is it possible to differentiate a nmap port scan from a syn flood attack?, Miriam Rico
Lint for nftables,
Stephen Satchell
BNF for nftables?,
Stephen Satchell
[nftables v0.9.2] hoplimit mutually exclusive with with saddr/daddr?,
ѽ҉ᶬḳ℠
nft -f fails to merge some chains in same table but defined in separate blocks,
Frank Myhr
[MAINTENANCE] migrating git.netfilter.org,
Pablo Neira Ayuso
nftables atomic updates,
Frank Myhr
Multiples Chain with same hook - Default-Behavior?, Thomas Luening
nft multiple port exception,
david@xxxxxxxxx
Bulk loading of IP addresses or subnets in nftables?,
Lars Noodén
manipulating the ttl,
Daniel Lakeland
nft icmp type all?,
Robert Sander
TCP 4 way handshake or TCP Split Handshake Attack,
Fatih USTA
Policy routing Docker host not forwarding return traffic if marked, Felipe Arturo Polanco
nftables: Allow NAT Access with Timeout,
Mike Dillinger
nftables equivalent for iptables -m recent,
Sig Pam
nftables static routing fails,
david NEW
[ANNOUNCE] ipset 7.5 released, Kadlecsik József
nft script file, using include with wildcards,
Alberto Spin
IPv6 parsing issues in conntrackd?, Nico Schottelius
nftables with secmark and ipsec, Christian Göttsche
Assertion error when using map,
Changli Gao
[nft 0.9.2] cannot get sets to work - Error: Could not process rule: Not supported,
ѽ҉ᶬḳ℠
RFC -- IPTABLES vs NFTABLES vs BPFILTER,
Stephen Satchell
Weird/High CPU usage caused by LOG target,
Tom Yan
geoip not working as expected, Felix
trying to duplicate udp packets destined for port 67 to port 6767 on same host,
Mike
xt_cluster for IPv6, Valentin Vidić
How to forward marked packets with same local IP?, Felipe Arturo Polanco
[PATCH] nftables: Bump dependency on libnftnl to 1.1.5, Jan-Philipp Litza
[ANNOUNCE] nftables 0.9.3 release,
Pablo Neira Ayuso
[ANNOUNCE] iptables 1.8.4 release, Phil Sutter
[ANNOUNCE] ebtables 2.0.11 release,
Pablo Neira Ayuso
[Index of Archives]
[Linux Netfilter Development]
[Advanced Routing & Traffice Control]
[Netem]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite Discussion]
[Linux Kernel Development]