Catching sneaky firewall drops with trace hooks
Networking & Firewall (Ss/Netstat/Iptables/Nftables/Curl)
Catching sneaky firewall drops with trace hooks
🧩 The Challenge
You’ve got an application that should be talking to a remote service, but you’re getting connection timeouts for no apparent reason. You know your local iptables rules are a complete mess of legacy garbage, but you can’t figure out which specific chain is nuking your packets.
💡 The Fix
Instead of guessing or tearing down your firewall, just hook into the raw trace facility to watch the kernel make its decisions in real time. It’s like having a debugger for your network rules.
nft add rule ip filter output tcp dport 80 meta nftrace set 1
nft monitor trace
⚙️ Why It Works
Setting the nftrace bit marks those specific packets so the kernel sends metadata about every single rule match to a monitor buffer. You’re effectively forcing the firewall to narrate exactly why it decided to drop your traffic.
🚀 Pro-Tip: Don’t forget to delete that trace rule when you’re done, or your kernel log will fill up faster than you can blink.
Linux Tips & Tricks | © ngelinux.com | 9/14/2026
