Re: Nftables ct count over 2 counter continues to trigger with only 1 connection

Fernando Fernandez Mancera <[email protected]> Thu, 23 Oct 2025 16:00:51 +0200
Newsgroups gmane.comp.security.firewalls.netfilter.general
Message-ID <[email protected]>

On 10/23/25 12:54 AM, [email protected] wrote:
> Hello,
> 
> I have read the documentation and asked on Stack Exchange but am unable to find an answer to the following behavior.
> 
> Given this table and chain where 123.123.123.123 is my own address:
> 
> table ip mytable {
>          chain mychain {
>                  type filter hook input priority filter; policy accept;
>                  ip saddr != 123.123.123.123 drop
>                  ip saddr 123.123.123.123 ct count over 2 counter
>          }
> }
> 
> I am establishing a varying number of TCP connections from my own address by connecting via SSH. These show up in "ss -at" and "conntrack -L" as well as disappear once disconnected - all as expected.
> 
> With 2 connections open I see "packets 0 bytes 0" on the counter. With 3 connections open I see "packets 6599 bytes 475441".
> 
> The question: when disconnecting 2 of the connections (from 3 total back to 1 total) the counter continues to increment. It triggers even when "ss -at" and "conntrack -L" show just one connection with no TIME_WAIT or other entries.
> 
> It even continues incrementing after a "conntrack -F" and often feels as though it is a one-way switch once the counter has triggered. Sometimes closing all connections (to 0 total) stops the counter from incrementing.
> 
> Is there an explanation as to this "ct count" behavior in more detail?
> 
> Thanks.

Yes, this seems buggy. I have reproduced this with upstream kernel and 
also on 5.10 so I guess this has been here for a long time. I am working 
now on a patch.

Thanks!