- Queries
- All Stories
- Search
- Advanced Search
- Transactions
- Transaction Logs
All Stories
Aug 16 2022
Aug 15 2022
PR for VyOS 1.3 https://github.com/vyos/vyos-1x/pull/1470
Nice. Is this syntax supported in vyos or it needs some development?
It is possible but with specific syntax
I found some examples:
nft insert rule ip filter VYOS_FW_FORWARD ip 'saddr & 0.255.0.255 != 0.11.0.13' counter
OK. I was trying to migrate from an EdgeRouter and this is a rule I used to have.
set service upnp rule 10 action allow set service upnp rule 10 external-port-range 1024-65536 set service upnp rule 10 internal-port-range 1024-65536 set service upnp rule 10 ip 10.0.0.1/24
@patrickli nftables is not engine for iptables. It is programs to work with netfilter
That's why I ask for the real example
root@r1:/home/vyos# nft insert rule ip6 filter INPUT ip6 saddr ::dead:beef/::ffff:ffff counter Error: syntax error, unexpected string, expecting number insert rule ip6 filter INPUT ip6 saddr ::dead:beef/::ffff:ffff counter ^^^^^^^^^^^ root@r1:/home/vyos#
Yeah nftables is just the engine for iptables. EdgeOS supports this syntax.
@patrickli In 1.4 we don't use iptables, we use nftables
LInk to nftables example will be helpful.
@patrickli Could you attach an example of VyOS configuration with set service upnp xxx
If you manually change upnpd.conf does it work correctly?
Aug 14 2022
@dmbaturin, here are the changes I made: https://github.com/vyos/vyos-build/compare/equuleus...fvlaicu:equuleus
I'm using the 1.4 kernel in 1.3.