Linux Netfilter / IP Tables
[Prev Page][Next Page]
Re: nftables and connection tracking, Pablo Neira Ayuso
ipsec matching in postrouting nat,
Marek Greško
WiFi Hotspot Disable Neighbor discovery,Ask,
Hooman
[ANNOUNCE] nftables 0.9.6 release, Pablo Neira Ayuso
loadbalance 2 internet links, paulo bruck
nftables drops related traffic,
Robin Kuiper
[ANNOUNCE] libnetfilter_queue 1.0.5 release, Florian Westphal
Looking to contribute to the nftables wiki, Gaelan Lloyd
Documentation.,
G.W. Haywood
[ANNOUNCE] nftables 0.9.5 release, Pablo Neira Ayuso
"Carrier Grade" NAT44 setup,
Maximilian Wilhelm
[ANNOUNCE] libnftnl 1.1.7 release, Pablo Neira Ayuso
[ANNOUNCE] libnetfilter_queue 1.0.4 release, Florian Westphal
Simplifying DNAT Rules using Maps,
Max Ehrlich
[ANNOUNCE] iptables 1.8.5 release, Phil Sutter
[MAINTENANCE] Shutting down FTP services at netfilter.org,
Pablo Neira Ayuso
Expressive limitation: (daddr,dport) <--> (daddr',dport'), Rick van Rein
Value too large for defined data type, ad^2
Let me make sure I have this right (fib),
Stephen Satchell
nft filter cgroup, Christian Schneider
Raw Expression for DNS name?,
ad^2
iif versus meta fib iif,
Stephen Satchell
WTF, over,
Stephen Satchell
Is this a correct usage of the FIB facility of NFTABLES? (BCP-38), Stephen Satchell
FIB filtering (comments, please) (reformatted), Stephen Satchell
FIB filtering (comments, please), Stephen Satchell
Timestamps, NFLOG, and ULOG,
Korodev
Fwd: Raw Expression matching DNS Query?, ad^2
nftables: defining variables containing ipv6 adresses,
Thomas Weberstaedt
saddr, daddr type determination, Stephen Satchell
Systemd, nftables, and iptables,
Stephen Satchell
- Re: Systemd, nftables, and iptables,
- Re: Systemd, nftables, and iptables, Reindl Harald
- Re: Systemd, nftables, and iptables, Alexander Dahl
- Re: Systemd, nftables, and iptables, Trent W. Buck
Netdev conf 0x14 update, Jamal Hadi Salim
Dynamic list for net's,
Іван Щербей
POSTROUTING doesn't apply on all outgoing packets, Walter Laub
-m statistic does not work with 5.6.8, Reindl Harald
nftables NAT & Gaming Consoles,
Mike Dillinger
nftables: Strange Error When Adding Element to Named Set,
Mike Dillinger
Correct usage of nf_ct_get,
b38911 Zxc
Firewall sometimes leaking,
Nick
[Help] Allow website using iptables,
Sơn Đỗ
Using the fib to classify endpoints., Stephen Satchell
Documentation Error on http://wiki.nftables.org/wiki-nftables/index.php/GeoIP_matching,
Bob and Sally Public
idempotent nft delete table? (or: why does "flush table" delete rules but keep chains?),
Trent W. Buck
cannot create a nat type base (pre/post routing) chain,
Norbert van Bolhuis
Multicast routed packets do not get SNAT translation performed, Stephen Deiters
Questions around the use of timestamps, Nikolaos Kakouros
nftables and traffic control utility to QoS,
d.gubin
conntrack traffic statistics and connlabel, Fatih USTA
has somebody an idea what fills up the log (5050/udp)?,
Walter H.
possible error in HOWTO, Fred Maranhão
ARP confirmed timestamp update on TCP data flow vs keep-alive, Steffen Heil (Mailinglisten)
[PATCH v1 1/1] Update download script for DBIP database, Philip Prindeville
[PATCH v1 1/1] update MaxMind URL's, Philip Prindeville
Is viewing a "candidate" ruleset in 'nft list ruleset' format possible?,
Martin Gignac
query re dynamic set and limiting,
James Bond
WARNING: at net/sched/sch_generic.c - Reproducible crash & rcu stalls, Christopher S. Aker
marking/routing packets breaks the conntrack rule for NAT, Mickael Bosch
Hello, I have some questions about flowtable., James Bond
validate IPsec outgoing packets using NFtables,
Olivier Alabeatrix
extending element timeout,
Alvaro Leiva
[ANNOUNCE] conntrack-tools 1.4.6, Pablo Neira Ayuso
[ANNOUNCE] libnetfilter_conntrack 1.0.8 release, Pablo Neira Ayuso
[ANNOUNCE] libnftnl 1.1.6 release, Pablo Neira Ayuso
[ANNOUNCE] nftables 0.9.4 release,
Pablo Neira Ayuso
[ANNOUNCE] nftlb 0.6 release,
Laura Garcia
netem qdisc destroys traffic in other tc classes (HFSC classes), kaskada
batch update of conntrack?, kaskada
Re: What is the BEST GUI frontend to iptables firewall?,
ѽ҉ᶬḳ℠
Re: What is the BEST GUI frontend to iptables firewall?, Daniel
Re: What is the BEST GUI frontend to iptables firewall?, Eric Garver
[libnftnl] documentation?,
ѽ҉ᶬḳ℠
A question about priority in chains,
darius
Ipv6tov4 address Dnat,
Zheng konia
tc question about ingress bandwidth splitting,
Philip Prindeville
[nftables 0.9.2 | flow table] check whether it works?,
ѽ҉ᶬḳ℠
TCP and UDP dport in the same rule,
Darius
[nftables 0.9.2 | flow table] dynamic (soft) NETDEV,
ѽ҉ᶬḳ℠
nftables 0.9.3, sets with concatentation,
Stefan Hartmann
Interface group ID in flow tables?, Robert White
Boundary Flag for "site" (IPv6) [Kernel Change?], Robert White
[nftables 0.9.2] NETDEV packet drop vs. packet capture visibility,
ѽ҉ᶬḳ℠
Advantage(s) of static over dynamic nftables sets?,
Frank Myhr
[nftables 0.9.2 | kernel 4.19.93] flowtable throws error on deployment (not on check however),
ѽ҉ᶬḳ℠
[nftables 0.9.2 | kernel 4.19.93] flowtable - number of devices limited (7)?,
ѽ҉ᶬḳ℠
[nftables 0.9.2 | kernel 4.19.93] dropping ct state untracked stops ipv6 connectivity,
ѽ҉ᶬḳ℠
Re: use libiptc to build a rule to allow tftp traffic,
Moyuan Chen
Restoring rulesets containing dynamic sets with counters,
Frank Myhr
nftables equivalent of "ipset test"?,
Frank Myhr
nft ingress won't work on wireless ?,
sean darcy
Set timeout, gc-interval and size parameters, Frank Myhr
use numgen to create address in rule,
Dennett Ingram
Found extra tables in nft ruleset,
Lars Noodén
Why inet table doesn't support nat prerouting chain?,
Glen Huang
LXD Container can't access trough host address, Franz Schneider
Is it possible to get a transparent proxy with Redsocks when using the new nftables?,
Verachten Bruno
nftables offload doesn't seem to work,
Patrick McLean
Demystifying sets,
jon_netfilter
wiki acess, pauloric
loadbalance with 2 or more links,
pauloric
[ANNOUNCE] ipset 7.6 released, Jozsef Kadlecsik
Typo in the 'Mangle TCP options' wiki pages, Pieter van Leuven
Waiting until first release of NFTABLES,
Stephen Satchell
Automatically maintaining unique list of addresses,
Lars Noodén
NFQUEUE/iptables and kernel warning messages for net/ipv4/tcp_output.c,
Vieri Di Paola
Resetting SKB CT, Mathew Heard
Problems with CONNTRACK --restore-mark, Bernd Jerzyna
Difficulties with ulog / NFCT,
Alessandro Vesely
nfnetlink: This library is not meant as a public API for application developers.,
Alessandro Vesely
[nftables 0.9.2] does jump require a kconf to be set to get it working?,
ѽ҉ᶬḳ℠
iptables MASQUERADE considering route source hints, Max Stritzinger
Does anybody experience kernel crush when 'ebtable -t nat -L',
양유석
Compiling nftables with stack-protector-strong fails checksec's canary check,
Glen Huang
[nftables] economics of reverse path filtering - FIB expression vs. kernel parameter,
ѽ҉ᶬḳ℠
nftables "native interface" for IPv6 NPT?,
Haochen Tong
Netfilter state synchronisation in IPv6 only networks?, Nico Schottelius
[firewall context] packet presentation for dual WAN interfaces on the same link - eth <> pppoe?,
ѽ҉ᶬḳ℠
Metering is not working with dynamic sets on nft v0.9.2,
darius
[nftables] inherent benefits from XDP?, ѽ҉ᶬḳ℠
[nftables] xtables-addons - GeoIP/ASN filter and lscan replicable?,
ѽ҉ᶬḳ℠
[nftables v0.9.2 | kernel 4.19.93] does redirect accept daddr?,
ѽ҉ᶬḳ℠
Redirect bridged traffic,
Jaga Doe
[nftables v0.9.2 | kernel 4.19.93] logging protocols in inet family table require explicit protocol statement?,
ѽ҉ᶬḳ℠
[nftables v0.9.2] inet <> ip | ip6 family tables processing order?,
ѽ҉ᶬḳ℠
[nftables v0.9.2 | kernel 4.19.93] MSS clamping rule possible in the inet family table?,
ѽ҉ᶬḳ℠
nftables simple configuration, Jaga Doe
nftables routing decision,
Иванов Роман
[nftables v0.9.2 | kernel 4.19.93] ICMPv6 ingress dropped despite accept rule,
ѽ҉ᶬḳ℠
Re: [nftables v0.9.2 | kernel 4.19.93] ICMPv6 ingress dropped despite accept rule, Duncan Roe
Is it possible to differentiate a nmap port scan from a syn flood attack?, Miriam Rico
Lint for nftables,
Stephen Satchell
BNF for nftables?,
Stephen Satchell
[nftables v0.9.2] hoplimit mutually exclusive with with saddr/daddr?,
ѽ҉ᶬḳ℠
nft -f fails to merge some chains in same table but defined in separate blocks,
Frank Myhr
[MAINTENANCE] migrating git.netfilter.org,
Pablo Neira Ayuso
nftables atomic updates,
Frank Myhr
Multiples Chain with same hook - Default-Behavior?, Thomas Luening
nft multiple port exception,
david@xxxxxxxxx
Bulk loading of IP addresses or subnets in nftables?,
Lars Noodén
manipulating the ttl,
Daniel Lakeland
nft icmp type all?,
Robert Sander
TCP 4 way handshake or TCP Split Handshake Attack,
Fatih USTA
Policy routing Docker host not forwarding return traffic if marked, Felipe Arturo Polanco
nftables: Allow NAT Access with Timeout,
Mike Dillinger
nftables equivalent for iptables -m recent,
Sig Pam
nftables static routing fails,
david NEW
[ANNOUNCE] ipset 7.5 released, Kadlecsik József
nft script file, using include with wildcards,
Alberto Spin
IPv6 parsing issues in conntrackd?, Nico Schottelius
nftables with secmark and ipsec, Christian Göttsche
Assertion error when using map,
Changli Gao
[nft 0.9.2] cannot get sets to work - Error: Could not process rule: Not supported,
ѽ҉ᶬḳ℠
RFC -- IPTABLES vs NFTABLES vs BPFILTER,
Stephen Satchell
Weird/High CPU usage caused by LOG target,
Tom Yan
geoip not working as expected, Felix
trying to duplicate udp packets destined for port 67 to port 6767 on same host,
Mike
xt_cluster for IPv6, Valentin Vidić
How to forward marked packets with same local IP?, Felipe Arturo Polanco
[PATCH] nftables: Bump dependency on libnftnl to 1.1.5, Jan-Philipp Litza
[ANNOUNCE] nftables 0.9.3 release,
Pablo Neira Ayuso
[ANNOUNCE] iptables 1.8.4 release, Phil Sutter
[ANNOUNCE] ebtables 2.0.11 release,
Pablo Neira Ayuso
[ANNOUNCE] arptables 0.0.5 release, Pablo Neira Ayuso
nftables: No prefixes in anonymous sets?,
Jan-Philipp Litza
WARNING: CPU: 9 PID: 0 at net/netfilter/nf_conntrack_core.c:977 __nf_conntrack_confirm+0x4e5/0x6f0 [nf_conntrack],
Harald Dunkel
Doubts about netfilter + nftables and module,
Elias Valea Peri
How to prevent SNAT rules from being applied to 'ICMP time exceeded' responses?, Gordon Fish
Mysql has problem with synproxy,
İbrahim Ercan
Netfilter hook doesn't see all packets,
Psyspy rambo
ipset bitmap:port question,
A L
Upgrading libnetfilter_queue to use nftables,
Alessandro Vesely
Trouble getting SYNPROXY to work.,
Pigi
ebtables dnat rule gets system frozen,
Tom Yan
Length module, docs "incorrect" or something else?, Andreas Sikkema
[ANNOUNCE] ipset 7.4 released, Kadlecsik József
Distinguish local from routed traffic, Robert Dahlem
IPv6 nft vs ip6tables - Local incompatibility ?,
Daniel Huhardeaux
Named sets with timeout,
Matt
Been having mail server issues so been unable to reply properly, Aaron Gray
understanding my MASQURADING and SNAT problem,
Aaron Gray
How to implement transparent proxy in bridge through nftables, Ttttabcd
Snapped nftables, Paweł Krawczyk
nftables v0.9.0 netlink: Error: set is not a map,
Daniel Huhardeaux
CFS for Netdev 0x14 open!, Jamal Hadi Salim
Status of BPFilter?, A L
Counting over a bridge, Cristian Morales Vega
flowtable breaks masquerade for dnat flows,
Jonathan Rudenberg
syn-flag-check from outside not working, Thomas Luening
nft - execute command without returning error,
Daniel Huhardeaux
nft and defined variables,
Daniel Huhardeaux
nft -- documentation on fib_addrtype missing, more data,
Stephen Satchell
nft -- documentation on fib_addrtype missing,
Stephen Satchell
nft tproxy without iproute2 rule,
Norman Rasmussen
TEE target and gateway as MAC address, Vieri Di Paola
Cannot add ip6 elements to a named set,
Matt
nft: auto-merge set doesn't merge overlapping intervals,
Richard Stanway
How can I block all traffic from an IP range, irrespective of origin, going to, or coming from, using nftables in Debian 10,
Jags
- Re: How can I block all traffic from an IP range, irrespective of origin, going to, or coming from, using nftables in Debian 10, zrm
- Re: How can I block all traffic from an IP range, irrespective of origin, going to, or coming from, using nftables in Debian 10, Jags
- Re: How can I block all traffic from an IP range, irrespective of origin, going to, or coming from, using nftables in Debian 10, Reindl Harald
- Re: How can I block all traffic from an IP range, irrespective of origin, going to, or coming from, using nftables in Debian 10, Jags
- Re: How can I block all traffic from an IP range, irrespective of origin, going to, or coming from, using nftables in Debian 10, Reindl Harald
- Re: How can I block all traffic from an IP range, irrespective of origin, going to, or coming from, using nftables in Debian 10, Jags
- Re: How can I block all traffic from an IP range, irrespective of origin, going to, or coming from, using nftables in Debian 10, Reindl Harald
- Re: How can I block all traffic from an IP range, irrespective of origin, going to, or coming from, using nftables in Debian 10, Jags
- Re: How can I block all traffic from an IP range, irrespective of origin, going to, or coming from, using nftables in Debian 10, Reindl Harald
- Re: How can I block all traffic from an IP range, irrespective of origin, going to, or coming from, using nftables in Debian 10, Neal P. Murphy
- Re: How can I block all traffic from an IP range, irrespective of origin, going to, or coming from, using nftables in Debian 10, Jags
iptables TEE target and system slowdown, Vieri Di Paola
NAT statements in nft command documentation are misleading, Ted Roo
[PATCH] ipset: Add wildcard support to net,iface,
Kristian Evensen
Intermix ip,ip6 saddr,
Anton Rieger
Regarding flowtables and conntrack, Otto Reinikainen
queue bypass not working?,
Charles Eidsness
nft set elements: Comment not available for elements?,
Bernd Naumann
How is nftables + IFB,
John Mok
[Index of Archives]
[Linux Netfilter Development]
[Advanced Routing & Traffice Control]
[Netem]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite Discussion]
[Linux Kernel Development]