Re: nftables RP filter and loopback

Slavko <[email protected]> Sat, 26 Apr 2025 11:40:51 +0200
Newsgroups gmane.comp.security.firewalls.netfilter.general
Message-ID <[email protected]>
Ahoj,

Dňa Sat, 26 Apr 2025 11:24:47 +0200 Florian Westphal <[email protected]>
napísal:

> You either have no conntrack active at all or you have another
> notrack rule in output ("lo" is picked up in output, not prerouting).

yes, you are right, i have opposite lo notrack in output chain and it
seems, that for "lo" <=> "lo" traffic it is enough (tested).

thanks

-- 
Slavko
https://www.slavino.sk