|
Packit |
c5a612 |
:input;type filter hook input priority 0
|
|
Packit |
c5a612 |
:ingress;type filter hook ingress device lo priority 0
|
|
Packit |
c5a612 |
|
|
Packit |
c5a612 |
*ip;test-ip4;input
|
|
Packit |
c5a612 |
*ip6;test-ip6;input
|
|
Packit |
c5a612 |
*inet;test-inet;input
|
|
Packit |
c5a612 |
*netdev;test-netdev;ingress
|
|
Packit |
c5a612 |
|
|
Packit |
c5a612 |
tcp dport set {1, 2, 3};fail
|
|
Packit |
c5a612 |
|
|
Packit |
c5a612 |
tcp dport 22;ok
|
|
Packit |
c5a612 |
tcp dport != 233;ok
|
|
Packit |
c5a612 |
tcp dport 33-45;ok
|
|
Packit |
c5a612 |
tcp dport != 33-45;ok
|
|
Packit |
c5a612 |
tcp dport { 33, 55, 67, 88};ok
|
|
Packit |
c5a612 |
tcp dport != { 33, 55, 67, 88};ok
|
|
Packit |
c5a612 |
tcp dport { 33-55};ok
|
|
Packit |
c5a612 |
tcp dport != { 33-55};ok
|
|
Packit |
c5a612 |
tcp dport {telnet, http, https} accept;ok;tcp dport { 443, 23, 80} accept
|
|
Packit |
c5a612 |
tcp dport vmap { 22 : accept, 23 : drop };ok
|
|
Packit |
c5a612 |
tcp dport vmap { 25:accept, 28:drop };ok
|
|
Packit |
c5a612 |
tcp dport { 22, 53, 80, 110 };ok
|
|
Packit |
c5a612 |
tcp dport != { 22, 53, 80, 110 };ok
|
|
Packit |
c5a612 |
# BUG: invalid expression type set
|
|
Packit |
c5a612 |
# nft: src/evaluate.c:975: expr_evaluate_relational: Assertion '0' failed.
|
|
Packit |
c5a612 |
|
|
Packit |
c5a612 |
tcp sport 22;ok
|
|
Packit |
c5a612 |
tcp sport != 233;ok
|
|
Packit |
c5a612 |
tcp sport 33-45;ok
|
|
Packit |
c5a612 |
tcp sport != 33-45;ok
|
|
Packit |
c5a612 |
tcp sport { 33, 55, 67, 88};ok
|
|
Packit |
c5a612 |
tcp sport != { 33, 55, 67, 88};ok
|
|
Packit |
c5a612 |
tcp sport { 33-55};ok
|
|
Packit |
c5a612 |
tcp sport != { 33-55};ok
|
|
Packit |
c5a612 |
tcp sport vmap { 25:accept, 28:drop };ok
|
|
Packit |
c5a612 |
|
|
Packit |
c5a612 |
tcp sport 8080 drop;ok
|
|
Packit |
c5a612 |
tcp sport 1024 tcp dport 22;ok
|
|
Packit |
c5a612 |
tcp sport 1024 tcp dport 22 tcp sequence 0;ok
|
|
Packit |
c5a612 |
|
|
Packit |
c5a612 |
tcp sequence 0 tcp sport 1024 tcp dport 22;ok
|
|
Packit |
c5a612 |
tcp sequence 0 tcp sport { 1024, 1022} tcp dport 22;ok;tcp sequence 0 tcp sport { 1022, 1024} tcp dport 22
|
|
Packit |
c5a612 |
|
|
Packit |
c5a612 |
tcp sequence 22;ok
|
|
Packit |
c5a612 |
tcp sequence != 233;ok
|
|
Packit |
c5a612 |
tcp sequence 33-45;ok
|
|
Packit |
c5a612 |
tcp sequence != 33-45;ok
|
|
Packit |
c5a612 |
tcp sequence { 33, 55, 67, 88};ok
|
|
Packit |
c5a612 |
tcp sequence != { 33, 55, 67, 88};ok
|
|
Packit |
c5a612 |
tcp sequence { 33-55};ok
|
|
Packit |
c5a612 |
tcp sequence != { 33-55};ok
|
|
Packit |
c5a612 |
|
|
Packit |
c5a612 |
tcp ackseq 42949672 drop;ok
|
|
Packit |
c5a612 |
tcp ackseq 22;ok
|
|
Packit |
c5a612 |
tcp ackseq != 233;ok
|
|
Packit |
c5a612 |
tcp ackseq 33-45;ok
|
|
Packit |
c5a612 |
tcp ackseq != 33-45;ok
|
|
Packit |
c5a612 |
tcp ackseq { 33, 55, 67, 88};ok
|
|
Packit |
c5a612 |
tcp ackseq != { 33, 55, 67, 88};ok
|
|
Packit |
c5a612 |
tcp ackseq { 33-55};ok
|
|
Packit |
c5a612 |
tcp ackseq != { 33-55};ok
|
|
Packit |
c5a612 |
|
|
Packit |
c5a612 |
- tcp doff 22;ok
|
|
Packit |
c5a612 |
- tcp doff != 233;ok
|
|
Packit |
c5a612 |
- tcp doff 33-45;ok
|
|
Packit |
c5a612 |
- tcp doff != 33-45;ok
|
|
Packit |
c5a612 |
- tcp doff { 33, 55, 67, 88};ok
|
|
Packit |
c5a612 |
- tcp doff != { 33, 55, 67, 88};ok
|
|
Packit |
c5a612 |
- tcp doff { 33-55};ok
|
|
Packit |
c5a612 |
- tcp doff != { 33-55};ok
|
|
Packit |
c5a612 |
|
|
Packit |
c5a612 |
# BUG reserved
|
|
Packit |
c5a612 |
# BUG: It is accepted but it is not shown then. tcp reserver
|
|
Packit |
c5a612 |
|
|
Packit |
c5a612 |
tcp flags { fin, syn, rst, psh, ack, urg, ecn, cwr} drop;ok
|
|
Packit |
c5a612 |
tcp flags != { fin, urg, ecn, cwr} drop;ok
|
|
Packit |
c5a612 |
tcp flags cwr;ok
|
|
Packit |
c5a612 |
tcp flags != cwr;ok
|
|
Packit |
c5a612 |
tcp flags == syn;ok
|
|
Packit |
c5a612 |
tcp flags & (syn|fin) == (syn|fin);ok;tcp flags & (fin | syn) == fin | syn
|
|
Packit |
c5a612 |
tcp flags & (fin | syn | rst | psh | ack | urg | ecn | cwr) == fin | syn | rst | psh | ack | urg | ecn | cwr;ok;tcp flags == 0xff
|
|
Packit |
c5a612 |
|
|
Packit |
c5a612 |
tcp window 22222;ok
|
|
Packit |
c5a612 |
tcp window 22;ok
|
|
Packit |
c5a612 |
tcp window != 233;ok
|
|
Packit |
c5a612 |
tcp window 33-45;ok
|
|
Packit |
c5a612 |
tcp window != 33-45;ok
|
|
Packit |
c5a612 |
tcp window { 33, 55, 67, 88};ok
|
|
Packit |
c5a612 |
tcp window != { 33, 55, 67, 88};ok
|
|
Packit |
c5a612 |
tcp window { 33-55};ok
|
|
Packit |
c5a612 |
tcp window != { 33-55};ok
|
|
Packit |
c5a612 |
|
|
Packit |
c5a612 |
tcp checksum 22;ok
|
|
Packit |
c5a612 |
tcp checksum != 233;ok
|
|
Packit |
c5a612 |
tcp checksum 33-45;ok
|
|
Packit |
c5a612 |
tcp checksum != 33-45;ok
|
|
Packit |
c5a612 |
tcp checksum { 33, 55, 67, 88};ok
|
|
Packit |
c5a612 |
tcp checksum != { 33, 55, 67, 88};ok
|
|
Packit |
c5a612 |
tcp checksum { 33-55};ok
|
|
Packit |
c5a612 |
tcp checksum != { 33-55};ok
|
|
Packit |
c5a612 |
|
|
Packit |
c5a612 |
tcp urgptr 1234 accept;ok
|
|
Packit |
c5a612 |
tcp urgptr 22;ok
|
|
Packit |
c5a612 |
tcp urgptr != 233;ok
|
|
Packit |
c5a612 |
tcp urgptr 33-45;ok
|
|
Packit |
c5a612 |
tcp urgptr != 33-45;ok
|
|
Packit |
c5a612 |
tcp urgptr { 33, 55, 67, 88};ok
|
|
Packit |
c5a612 |
tcp urgptr != { 33, 55, 67, 88};ok
|
|
Packit |
c5a612 |
tcp urgptr { 33-55};ok
|
|
Packit |
c5a612 |
tcp urgptr != { 33-55};ok
|
|
Packit |
c5a612 |
|
|
Packit |
c5a612 |
tcp doff 8;ok
|