Re: nftables RP filter and loopback
Slavko <[email protected]> Sat, 26 Apr 2025 11:40:51 +0200
| Newsgroups | gmane.comp.security.firewalls.netfilter.general |
|---|---|
| Message-ID | <[email protected]> |
Ahoj, Dňa Sat, 26 Apr 2025 11:24:47 +0200 Florian Westphal <[email protected]> napísal: > You either have no conntrack active at all or you have another > notrack rule in output ("lo" is picked up in output, not prerouting). yes, you are right, i have opposite lo notrack in output chain and it seems, that for "lo" <=> "lo" traffic it is enough (tested). thanks -- Slavko https://www.slavino.sk