我在 nftables 中有两个表:
$ sudo nft list tables
table inet filter
table ip nat
表格nat
可以列得很好:
$ sudo nft list table nat
table ip nat {
chain prerouting {
type nat hook prerouting priority filter; policy accept;
<output truncated>
}
chain postrouting {
type nat hook postrouting priority srcnat; policy accept;
<output truncated>
}
}
但不是filter
表格:
$ sudo nft list table filter
Error: No such file or directory
list table filter
^^^^^^
这意味着我无法在命令行添加新规则:
$ sudo nft add rule filter forward oif <interface> ip saddr <ip> accept
Error: No such file or directory; did you mean table ‘filter’ in family inet?
add rule filter forward oif <interface> ip saddr <ip> accept
^^^^^^
这是我第一次尝试使用nft
命令行,到目前为止,我只有静态配置,/etc/nftables.conf
这已经足够了。这是怎么回事?