<html>
<head>
<base href="https://bugzilla.netfilter.org/" />
</head>
<body>
<p>
<div>
<b><a class="bz_bug_link
bz_status_NEW "
title="NEW - Named sets - Use flags interval and dynamic"
href="https://bugzilla.netfilter.org/show_bug.cgi?id=1711#c3">Comment # 3</a>
on <a class="bz_bug_link
bz_status_NEW "
title="NEW - Named sets - Use flags interval and dynamic"
href="https://bugzilla.netfilter.org/show_bug.cgi?id=1711">bug 1711</a>
from <span class="vcard"><a class="email" href="mailto:nicolasfort1988@gmail.com" title="nicolasfort1988@gmail.com">nicolasfort1988@gmail.com</a>
</span></b>
<pre>No,interval seems not enough to be able to update set using firewall rules.
For example:
vyos@vyos:~$ sudo nft list table ip filter
table ip filter {
set FOO-1 {
type ipv4_addr
flags interval
}
set FOO-2 {
type ipv4_addr
size 65535
flags dynamic
}
chain FOO {
update @FOO-2 { ip saddr }
}
}
vyos@vyos:~$ sudo nft add rule ip filter FOO set update ip daddr @FOO-2
vyos@vyos:~$ sudo nft add rule ip filter FOO set update ip daddr @FOO-1
Error: Could not process rule: Operation not supported
add rule ip filter FOO set update ip daddr @FOO-1
^^^^^^^^^^^^^^^^^^^^^^^^^^
vyos@vyos:~$
As you can see, update set FOO-1 through firewall rules is not possible
(doesn't have dynamic flag), while updating set FOO-2 is allowed.</pre>
</div>
</p>
<hr>
<span>You are receiving this mail because:</span>
<ul>
<li>You are watching all bug changes.</li>
</ul>
</body>
</html>