nftables
nftables copied to clipboard
synproxy support
Based on what I can tell this library doesn't support synproxy as a part of a rule. For example:
tcp dport 8888 ct state invalid,untracked synproxy mss 1460 wscale 7 timestamp sack-perm
Is that correct? If so, I would be happy to work on a PR for support if folks are interested. Thanks!
Can’t find the word “synproxy” mentioned in the code base, so yes, sounds like it’s not supported.
Feel free to send a PR!
:+1:
Synproxy/syncookie support in nftables exists but is no longer needed due to lockless listener changes for TCP https://lwn.net/Articles/659199/