[Bug 1305] Rules in first chain same hook ignored if second chain has policy drop

bugzilla-daemon at netfilter.org bugzilla-daemon at netfilter.org
Mon Feb 8 03:13:47 CET 2021


https://bugzilla.netfilter.org/show_bug.cgi?id=1305

--- Comment #17 from Pablo Neira Ayuso <pablo at netfilter.org> ---
(In reply to Frank Myhr from comment #13)
> Created attachment 623 [details]
> netfilter / nftables packet flow diagram
> 
> My understanding of netfilter / nftables packet flow. (Tangential topic here
> I know, so feel free to send suggestions / corrections via email instead of
> this bug report.)

I have just updated the wiki page, please see:

https://wiki.nftables.org/wiki-nftables/index.php/Netfilter_hooks
https://people.netfilter.org/pablo/nf-hooks.png

Let me know if you have comments on this one / find mistakes to fix this.

Routing comes before the output hook, that's why there is a 'route' chain type
for output basechains.

-- 
You are receiving this mail because:
You are watching all bug changes.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.netfilter.org/pipermail/netfilter-buglog/attachments/20210208/c35d125f/attachment.html>


More information about the netfilter-buglog mailing list