You are not logged in.
I am trying to build a simple stateful firewall following the Arch Linux nftables guide. After completing the guide and rebooting my machine, systemd failed to load the nftables.service. To troubleshoot the error I ran:
systemctl status nftablesThis is the ouput:
Starting Netfilter Tables ..../etc/nftables.conf:7:17-25: Error: conflicting protocols specified: inet-service v. icmpThe error message is referring to the rules that I set for accepting new pings (icmp).
I essentially copied and pasted every line of the guide into my command line using the nft cli, and then made my changes permanent with
# nft list ruleset > /etc/nftables.conf.
I will not burden the reader with each-and-every line. Instead I will provide my final output.
Here is my nftables.conf file after completing the guide:
table inet filter {
chain input {
type filter hook input priority 0; policy drop;
ct state established,related accept
iif "lo" accept
ct state invalid drop
icmp type echo-request ct state new accept
ip protocol udp ct state new jump UDP
tcp flags & (fin | syn | rst | ack) == syn ct state new jump TCP
ip protocol udp reject
ip protocol tcp reject with tcp reset
meta nfproto ipv4 counter packets 0 bytes 0 reject with icmp type prot-unreachable
}
chain forward {
type filter hook forward priority 0; policy drop;
}
chain output {
type filter hook output priority 0; policy accept;
}
chain TCP {
tcp dport http accept
tcp dport https accept
tcp dport ssh accept
tcp dport domain accept
}
chain UDP {
tcp dport domain accept
}
}Basically, it creates the table filter of the family inet. There are 5 chains. Three are the base input, forward, and output, chains, and the remaining 2 are TCP and UDP chains. Once again the rules are copied straight from the guide.
Any thoughts? Please let me know if I need to provide any additional information. Thank you in advance.
Last edited by justinnoor (2017-12-03 05:42:22)
Offline
I haven't spent the time to sit down and learn nftables yet, but the error says it is on line 7. And, comparing your config to the wiki, it looks like you're missing a "ip protocol icmp" at the beginning of line 7, right before "icmp type echo-request ct state new accept", right?
In other words, it looks like you ran:
nft add rule inet filter input icmp type echo-request ct state new acceptinstead of
nft add rule inet filter input ip protocol icmp icmp type echo-request ct state new acceptLast edited by GenkiSky (2017-12-03 18:17:14)
Offline
Thank you so much for your time in responding. Yes you are correct. The ip protocol is missing from line 7, and also from line 9. I looked into this before posting and found that this is how the nft cli is outputting to nftables.conf.
You can verify this by running:
nft flush ruleset
nft add table inet filter
nft add rule inet filter input ip protocol icmp icmp type echo-request ct state new accept
nft list rulesetYou'll find that the ip protocol portion of the command is missing.
I did, however, try adding ip protocol manually to line 7 in nftables.conf and systemd still failed to load nftables.service. So for now I'm just not using line 7. I'm thinking about contacting netfilter.org. Thanks again. Take care.
Offline