Kalcifer OP , (edited )
@Kalcifer@sh.itjust.works avatar

Input means the packet stops at the router

Ah okay, so if Output: accept is still enabled, then, even though Input: reject is set, the packet can still use the router as a hop in it’s journey to a device on the router’s network? It just can’t stop at the router? I guess that makes sense because the device on the routers network is addressed by a port which is a layer above the IP address, so it wouldn’t even have a notion of addressing the router unless it just specifies the raw IP.

[EDIT (2024-02-08T00:21Z): Redacted this paragraph after re-reading this comment.]Another thing that is confusing me is the setting for Forward. I would assume that if a packet is destined for a device on the router’s network, then that packet is being forwarded from wan to lan, and if Masquerading is enabled, then the destination IP will be modified by the router. But, in the example image we have that Forward: reject is set. How does the packet get forwarded between interfaces if forwarding is disabled?

[EDIT (2024-02-08T00:21Z): Added the following quote, and response.]

When forward on the wan interface is set to reject, it essentially means no device from outside may initiate a connection. However, they may respond to already opened connection.

How does the router differentiate between the two? If I remember correctly, nftbales uses conntrack to track this sort of stuff. I would guess that the router does the same?

[EDIT (2024-02-08T00:26Z): Added the following update.]

nftbales uses conntrack to track this sort of stuff. I would guess that the router does the same?

When I was looking through the settings for the second row, I came across the following setting:

https://sh.itjust.works/pictrs/image/dc459644-af01-48e4-aa00-a9b9a8f54e18.webp

I believe that this setting is accomplishing the behaviour that you described (not allowing connections from wan, but still allowing responses). Correct?

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • [email protected]
  • All magazines