Skip to content

default input policy is not realized #11

@toralf

Description

@toralf

I do have

  iptables -P INPUT  ${DEFAULT_POLICY_INPUT:-DROP}

here https://github.com/toralf/torutils/blob/main/ipv4-rules.sh#L6

and verified it

Chain INPUT (policy DROP 110 packets, 6110 bytes)
 pkts bytes target     prot opt in     out     source               destination

but I do get from the exporter:

 # curl -s localhost:9455/metrics  | grep -i policy | grep INPUT
ip6tables_chain_bytes_total{chain="INPUT",policy="ACCEPT",table="filter"} 0
ip6tables_chain_packets_total{chain="INPUT",policy="ACCEPT",table="filter"} 0
iptables_chain_bytes_total{chain="INPUT",policy="ACCEPT",table="filter"} 5294
iptables_chain_packets_total{chain="INPUT",policy="ACCEPT",table="filter"} 90

I had similar issue with the rule values too.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions