Override nftables blocktype in jail.local? #3698
Closed
jhgarrison
started this conversation in
General
Replies: 1 comment
-
Yes, all parameters can be supplied from jail.local. Line 212 in 0c125ec And you can do it for [DEFAULT]
banaction = nftables[mode=multiport, blocktype="counter reject"]
banaction_allports = nftables[mode=allports, blocktype="counter reject"]
[some-jail]
action_ = %(known/action_)[blocktype="<known/blocktype> with whatever"]
[other-jail]
# single action (overwrite default):
action = %(known/action_)[blocktype="<known/blocktype> with whatever"]
# or single action (all parameters here):
action = nftables[mode=allports, port="%(port)s", protocol="%(protocol)s", chain="%(chain)s", blocktype="reject with whatever"] However if you'd need it rather conditionally, e. g. depending on IP-family (like below), you'd need to do it in the local action: [Init]
blocktype = reject with icmp type host-unreachable
[Init?family=inet6]
blocktype = reject with icmpv6 type no-route You can also use |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Is it possible to override an nftables.conf [Init] parameter (blocktype=) in jail.local, or do I need to create action.d/nftables.local?
If so, what is the correct syntax?
Beta Was this translation helpful? Give feedback.
All reactions