-
-
Notifications
You must be signed in to change notification settings - Fork 521
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
System firewall rules not working #951
Comments
Hi @Am0g-us ,
but according to the rules posted it's set to accept:
Anyway, I'd suggest you to perform a test with another port and host, for example: Open a local port with netcat, and verify that you can connect: Then:
I also would suggest to stop the dockers containers, and any other service, to be sure that only opensnitch rules are present. |
Nft after set to deny
And i cannot access my ports (55555, 16804, 1599) |
mmmh, remove these rules please:
And add a new rule via Firewall -> New rule with these parameters: If the port is not TCP use UDP, but only add 1 rule of DST PORT. |
I removed and setup separated rules. And i can accept connections outside
|
great! did you try it with the other ports? |
If I create a rule for tcp and udp at the same time, I cannot accept connections. If I create separate rules for tcp and udp, I can accept connections |
Ok! For now you'll have to do it in this way. Adding a rule for both udp and tcp on the same rule is not supported. I'll investigate how to do it. |
I've added the option to allow ports by TCP+UDP. Thank you for reporting this! |
Please, check the FAQ and Known Problems pages before creating the bug report:
https://github.com/evilsocket/opensnitch/wiki/FAQs
https://github.com/evilsocket/opensnitch/wiki/Known-problems
Describe the bug
The system firewall settings does not work properly
Include the following information:
To Reproduce
Steps to reproduce the behavior:
Screenshots
Additional context
The screenshot shows the created rule. I cannot accept connections on these ports. I am also attaching all the nft rules in the system. This is one rule as an example, all the others don't work either
The text was updated successfully, but these errors were encountered: