请看我的nftables如下
# Warning: table ip6 filter is managed by iptables-nft, do not touch!
table ip6 filter {
chain INPUT {
type filter hook input priority filter; policy accept;
udp sport 5887 udp dport 5888 counter packets 4 bytes 3136 accept
}
chain FORWARD {
type filter hook forward priority filter; policy accept;
tcp flags syn / syn,rst counter packets 0 bytes 0 tcp option maxseg size set rt mtu
tcp flags syn / syn,rst counter packets 0 bytes 0 tcp option maxseg size set rt mtu
}
chain OUTPUT {
type filter hook output priority filter; policy accept;
}
}
注意INPUT Chain里的第二条UDP规则,counter显示通过了4个包,诡异的地方在于,
我写了个简单程序监听UDP 5888端口,结果啥也没收到,这包有可能是在什么地方
被抛弃了呢?
--
FROM 61.48.18.52