You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I started testing nochainedterms option for Speedway target and something looks weird to me: after each term we still render a jump statement to the same chain...
Here is the output for a simple 7 terms policy:
:INPUT DROP [0:0]
-A INPUT -p all -m state --state NEW,ESTABLISHED,RELATED -o lo -j ACCEPT
-A INPUT -j INPUT
-A INPUT -p all -m state --state ESTABLISHED,RELATED -j ACCEPT
-A INPUT -j INPUT
-A INPUT -p tcp -m multiport --dports 22,5666,9094,9100 -s 192.168.0.0/23 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p tcp -m multiport --dports 22,5666,9094,9100 -s 192.168.128.0/23 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p tcp -m multiport --dports 22,5666,9094,9100 -s 192.168.136.0/23 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p tcp -m multiport --dports 22,5666,9094,9100 -s 192.168.192.0/23 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
-A INPUT -j INPUT
-A INPUT -p udp --dport 9094 -s 192.168.0.0/23 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p udp --dport 9094 -s 192.168.128.0/23 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p udp --dport 9094 -s 192.168.136.0/23 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p udp --dport 9094 -s 192.168.192.0/23 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
-A INPUT -j INPUT
-A INPUT -p tcp --dport 8080 -s 192.168.8.18/32 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p tcp --dport 8080 -s 192.168.72.24/32 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
-A INPUT -j INPUT
-A INPUT -p tcp --dport 5045 -s 192.168.17.11/32 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p tcp --dport 5045 -s 192.168.81.59/32 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p tcp --dport 5045 -s 192.168.145.59/32 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p tcp --dport 5045 -s 192.168.160.31/32 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
-A INPUT -j INPUT
-A INPUT -p all -j LOG --log-prefix INPUT
-A INPUT -p all -j DROP
-A INPUT -j INPUT
iptables target doesn't have the same issue.
Thx for checking.
The text was updated successfully, but these errors were encountered:
I started testing
nochainedterms
option for Speedway target and something looks weird to me: after each term we still render a jump statement to the same chain...Here is the output for a simple 7 terms policy:
iptables target doesn't have the same issue.
Thx for checking.
The text was updated successfully, but these errors were encountered: