0

According to https://wiki.nftables.org/wiki-nftables/index.php/Flowtables, flowtables reside in the ingress hook. So, does that mean if connection is picked up by the flowtable, it will not be processed by any other rules in prerouting, input, etc.?

user762750
  • 181
  • 1
  • 10

1 Answers1

1

As said in the nftables wiki, you will only offload established connections. So yes, no further rule will be applied. Although, since you are offloading established rules, it is only offloaded once the flow has been accepted, natted, marked, and so on.

setenforce 1
  • 1,200
  • 6
  • 10