You are not logged in.

#1 2017-12-03 05:37:14

justinnoor
Member
Registered: 2017-12-02
Posts: 5

Nftables error: conflicting protocols specified: inet-service v. icmp

I am trying to build a simple stateful firewall following the Arch Linux nftables guide. After completing the guide and rebooting my machine, systemd failed to load the nftables.service. To troubleshoot the error I ran:

systemctl status nftables

This is the ouput:

Starting Netfilter Tables ....
/etc/nftables.conf:7:17-25: Error: conflicting protocols specified: inet-service v. icmp

The error message is referring to the rules that I set for accepting new pings (icmp).

I essentially copied and pasted every line of the guide into my command line using the nft cli, and then made my changes permanent with

# nft list ruleset > /etc/nftables.conf

.

I will not burden the reader with each-and-every line. Instead I will provide my final output.
Here is my nftables.conf file after completing the guide:

table inet filter {
    chain input {
        type filter hook input priority 0; policy drop;
        ct state established,related accept
        iif "lo" accept
        ct state invalid drop
        icmp type echo-request ct state new accept
        ip protocol udp ct state new jump UDP
        tcp flags & (fin | syn | rst | ack) == syn ct state new jump TCP
        ip protocol udp reject
        ip protocol tcp reject with tcp reset
        meta nfproto ipv4 counter packets 0 bytes 0 reject with icmp type prot-unreachable
    }

    chain forward {
        type filter hook forward priority 0; policy drop;
    }

    chain output {
        type filter hook output priority 0; policy accept;
    }

    chain TCP {
        tcp dport http accept
        tcp dport https accept
        tcp dport ssh accept
        tcp dport domain accept
    }

    chain UDP {
        tcp dport domain accept
    }
}

Basically, it creates the table filter of the family inet. There are 5 chains. Three are the base input, forward, and output, chains, and the remaining 2 are TCP and UDP chains. Once again the rules are copied straight from the guide.

Any thoughts? Please let me know if I need to provide any additional information. Thank you in advance.

Last edited by justinnoor (2017-12-03 05:42:22)

Offline

#2 2017-12-03 18:17:02

GenkiSky
Member
From: This account is henceforth dis
Registered: 2017-04-04
Posts: 82

Re: Nftables error: conflicting protocols specified: inet-service v. icmp

I haven't spent the time to sit down and learn nftables yet, but the error says it is on line 7. And, comparing your config to the wiki, it looks like you're missing a "ip protocol icmp" at the beginning of line 7, right before "icmp type echo-request ct state new accept", right?

In other words, it looks like you ran:

nft add rule inet filter input icmp type echo-request ct state new accept

instead of

nft add rule inet filter input ip protocol icmp icmp type echo-request ct state new accept

Last edited by GenkiSky (2017-12-03 18:17:14)

Offline

#3 2017-12-04 03:31:34

justinnoor
Member
Registered: 2017-12-02
Posts: 5

Re: Nftables error: conflicting protocols specified: inet-service v. icmp

Thank you so much for your time in responding. Yes you are correct. The ip protocol is missing from line 7, and also from line 9. I looked into this before posting and found that this is how the nft cli is outputting to nftables.conf.

You can verify this by running:

nft flush ruleset
nft add table inet filter
nft add rule inet filter input ip protocol icmp icmp type echo-request ct state new accept
nft list ruleset

You'll find that the ip protocol portion of the command is missing.

I did, however, try adding ip protocol manually to line 7 in nftables.conf and systemd still failed to load nftables.service. So for now I'm just not using line 7. I'm thinking about contacting netfilter.org. Thanks again. Take care.

Offline

Board footer

Powered by FluxBB