Re: Nftables ct count over 2 counter continues to trigger with only 1 connection

Pablo Neira Ayuso <[email protected]> Thu, 23 Oct 2025 13:42:03 +0200
Newsgroups gmane.comp.security.firewalls.netfilter.general
Message-ID <aPoUi7Uqienwt-Vq@calendula>
Hi,

On Thu, Oct 23, 2025 at 12:54:53AM +0200, [email protected] wrote:
> Hello,
> 
> I have read the documentation and asked on Stack Exchange but am unable to find an answer to the following behavior.
> 
> Given this table and chain where 123.123.123.123 is my own address:
> 
> table ip mytable {
>         chain mychain {
>                 type filter hook input priority filter; policy accept;
>                 ip saddr != 123.123.123.123 drop
>                 ip saddr 123.123.123.123 ct count over 2 counter
>         }
> }
> 
> I am establishing a varying number of TCP connections from my own address by connecting via SSH. These show up in "ss -at" and "conntrack -L" as well as disappear once disconnected - all as expected.
> 
> With 2 connections open I see "packets 0 bytes 0" on the counter. With 3 connections open I see "packets 6599 bytes 475441".
> 
> The question: when disconnecting 2 of the connections (from 3 total back to 1 total) the counter continues to increment. It triggers even when "ss -at" and "conntrack -L" show just one connection with no TIME_WAIT or other entries.
> 
> It even continues incrementing after a "conntrack -F" and often feels as though it is a one-way switch once the counter has triggered. Sometimes closing all connections (to 0 total) stops the counter from incrementing.
> 
> Is there an explanation as to this "ct count" behavior in more detail?

This behaviour looks buggy, I am trying to narrow down the issue.