Re: nftables RP filter and loopback

Slavko <[email protected]> Tue, 22 Apr 2025 12:32:04 +0000
Newsgroups gmane.comp.security.firewalls.netfilter.general
Message-ID <[email protected]>
On 22. apríla 2025 11:43:52 UTC, Florian Westphal <[email protected]> wrote:
>Slavko <[email protected]> wrote:

>This is an input chain.  The loopback bypass is restricted
>to PRE_ROUTING before v6.15-rc1.

Uh, oh, ah, i checked everything except this and i have in my
notes something as "fib outside prerouting can provide not
expected results" (without explanation), now i understand what
happen and too what that note means ;-)

Thanks, i changed hook to prerounting and now it works as
expected.

>(This is an oversight, originally fib was rejected in input chain, and
>when that restriction got lifted the lo bypass check wasn't adjusted).

I didn' use nftables in that time, thus i cannot compare
behavior. Just to confirm that i understund you properly:

+ from 6.15 it will work even in input hook and lo as expected
+ before 6.15 it doesn't work (properly) outside of prerouting
  hook only with lo traffic (other ifaces works)

regards


-- 
Slavko
https://www.slavino.sk/