Re: nftables RP filter and loopback
Slavko <[email protected]> Tue, 22 Apr 2025 12:32:04 +0000
| Newsgroups | gmane.comp.security.firewalls.netfilter.general |
|---|---|
| Message-ID | <[email protected]> |
On 22. aprÃla 2025 11:43:52 UTC, Florian Westphal <[email protected]> wrote: >Slavko <[email protected]> wrote: >This is an input chain. The loopback bypass is restricted >to PRE_ROUTING before v6.15-rc1. Uh, oh, ah, i checked everything except this and i have in my notes something as "fib outside prerouting can provide not expected results" (without explanation), now i understand what happen and too what that note means ;-) Thanks, i changed hook to prerounting and now it works as expected. >(This is an oversight, originally fib was rejected in input chain, and >when that restriction got lifted the lo bypass check wasn't adjusted). I didn' use nftables in that time, thus i cannot compare behavior. Just to confirm that i understund you properly: + from 6.15 it will work even in input hook and lo as expected + before 6.15 it doesn't work (properly) outside of prerouting hook only with lo traffic (other ifaces works) regards -- Slavko https://www.slavino.sk/