informatique:reseau:nftables
Différences
Ci-dessous, les différences entre deux révisions de la page.
| Prochaine révision | Révision précédente | ||
| informatique:reseau:nftables [28/09/2026 11:08] – créée cyrille | informatique:reseau:nftables [28/09/2026 11:23] (Version actuelle) – [Tips] cyrille | ||
|---|---|---|---|
| Ligne 4: | Ligne 4: | ||
| + | ===== Tips ===== | ||
| + | |||
| + | <code bash> | ||
| + | # Lister les tables | ||
| + | $ sudo nft list tables | ||
| + | table inet filter | ||
| + | table ip crowdsec | ||
| + | table ip6 crowdsec6 | ||
| + | |||
| + | # lister les règles (peu être très long si crowdsec ou autre IDS -> dump = 2Mo ) | ||
| + | $ sudo nft list ruleset | ||
| + | |||
| + | table inet filter { | ||
| + | chain input { | ||
| + | type filter hook input priority filter; policy accept; | ||
| + | } | ||
| + | |||
| + | chain forward { | ||
| + | type filter hook forward priority filter; policy accept; | ||
| + | } | ||
| + | |||
| + | chain output { | ||
| + | type filter hook output priority filter; policy accept; | ||
| + | } | ||
| + | } | ||
| + | table ip crowdsec { | ||
| + | counter processed { | ||
| + | packets 3593 bytes 7549768 | ||
| + | } | ||
| + | |||
| + | counter crowdsec-blacklists-CAPI { | ||
| + | packets 0 bytes 0 | ||
| + | } | ||
| + | |||
| + | counter crowdsec-blacklists-lists-firehol_greensnow { | ||
| + | packets 3 bytes 156 | ||
| + | } | ||
| + | |||
| + | counter crowdsec-blacklists-lists-otx-webscanners { | ||
| + | packets 0 bytes 0 | ||
| + | } | ||
| + | |||
| + | counter crowdsec-blacklists-crowdsec { | ||
| + | packets 0 bytes 0 | ||
| + | } | ||
| + | |||
| + | set crowdsec-blacklists-CAPI { | ||
| + | type ipv4_addr | ||
| + | flags timeout | ||
| + | elements = { 1.9.211.178 timeout 6d17h45m15s expires 6d17h38m17s708ms, | ||
| + | set crowdsec-blacklists-crowdsec { | ||
| + | type ipv4_addr | ||
| + | flags timeout | ||
| + | elements = { 41.43.191.126 timeout 15m45s expires 8m47s576ms } | ||
| + | } | ||
| + | |||
| + | chain crowdsec-chain-input { | ||
| + | type filter hook input priority filter - 10; policy accept; | ||
| + | counter name " | ||
| + | ip saddr @crowdsec-blacklists-CAPI counter name " | ||
| + | ip saddr @crowdsec-blacklists-lists-firehol_greensnow counter name " | ||
| + | ip saddr @crowdsec-blacklists-lists-otx-webscanners counter name " | ||
| + | ip saddr @crowdsec-blacklists-crowdsec counter name " | ||
| + | } | ||
| + | |||
| + | chain crowdsec-chain-forward { | ||
| + | type filter hook forward priority filter - 10; policy accept; | ||
| + | counter name " | ||
| + | ip saddr @crowdsec-blacklists-CAPI counter name " | ||
| + | ip saddr @crowdsec-blacklists-lists-firehol_greensnow counter name " | ||
| + | ip saddr @crowdsec-blacklists-lists-otx-webscanners counter name " | ||
| + | ip saddr @crowdsec-blacklists-crowdsec counter name " | ||
| + | } | ||
| + | } | ||
| + | table ip6 crowdsec6 { | ||
| + | counter processed { | ||
| + | packets 17416 bytes 1282930 | ||
| + | } | ||
| + | |||
| + | counter crowdsec6-blacklists-CAPI { | ||
| + | packets 0 bytes 0 | ||
| + | } | ||
| + | |||
| + | set crowdsec6-blacklists-CAPI { | ||
| + | type ipv6_addr | ||
| + | flags timeout | ||
| + | elements = { 2001: | ||
| + | chain crowdsec6-chain-input { | ||
| + | type filter hook input priority filter - 10; policy accept; | ||
| + | counter name " | ||
| + | ip6 saddr @crowdsec6-blacklists-CAPI counter name " | ||
| + | } | ||
| + | |||
| + | chain crowdsec6-chain-forward { | ||
| + | type filter hook forward priority filter - 10; policy accept; | ||
| + | counter name " | ||
| + | ip6 saddr @crowdsec6-blacklists-CAPI counter name " | ||
| + | } | ||
| + | } | ||
| + | |||
| + | </ | ||
informatique/reseau/nftables.1790586517.txt.gz · Dernière modification : de cyrille
