LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 05-10-2018, 03:40 AM   #1
abzalute
LQ Newbie
 
Registered: May 2018
Posts: 1

Rep: Reputation: Disabled
Query regarding behaviour of Nftables over Iptables


Hi,

We had a query regarding rate limiting feature in Nftables. We are using Nft version 0.8.3 on Ubuntu 17.01 and the kernel is 4.13.0.32.
Certain rate-limiting rules have been configured for ICMP traffic as shown below:

chain INGRESS_ECHO_REQUEST {
ct state { established, new} limit rate 25/second burst 8 packets counter packets 0 bytes 0 accept # handle 42
counter packets 0 bytes 0 jump INGRESS_RATELIMIT_CHAIN # handle 43
}


The number of packets rate-limited when using Iptables is vastly different when compared to Nftables. The attachment shows the traffic performance of the two.


We are unable to figure out why Nftables accepts an extra 32 packets in each case. We are at a crucial juncture in our project and would be really grateful if you could help us figure out this issue. Else there is a serious possibility of scrapping Nftables and switching back to Iptables.
Attached Thumbnails
Click image for larger version

Name:	Capture.PNG
Views:	12
Size:	18.6 KB
ID:	27588  

Last edited by abzalute; 05-10-2018 at 03:54 AM. Reason: Table is not displayed properly
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Help to Convert some iptables NAT rules to nftables netpumber Linux - Server 1 03-08-2017 03:51 PM
[SOLVED] translation from iptables to nftables kikilinux Linux - Security 3 12-17-2014 02:12 PM
[SOLVED] what is advantage of nftables over iptables packet filter ? kikilinux Linux - Security 1 10-01-2014 03:26 PM
NFTables To Replace iptables In the Linux Kernel jeremy Linux - News 0 10-21-2013 11:02 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 05:57 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration