Ability to drop packets by TCP MSS size
% nft add rule inet filter input tcp flags syn tcp option maxseg size 1-500 drop
Ability to drop packets by TCP MSS size
% nft add rule inet filter input tcp flags syn tcp option maxseg size 1-500 drop
PR https://github.com/vyos/vyos-1x/pull/1478
set firewall name FOO rule 10 action 'drop' set firewall name FOO rule 10 protocol 'tcp' set firewall name FOO rule 10 tcp flags syn set firewall name FOO rule 10 tcp mss '1-500'
nft:
vyos@r14# sudo nft -s list table ip filter table ip filter { ... chain NAME_FOO { tcp flags & syn == syn tcp option maxseg size 1-500 counter drop comment "FOO-10" counter return comment "FOO default-action accept" } }