Networking & Firewall (Ss/Netstat/Iptables/Nftables/Curl)
Catching sneaky firewall drops with trace hooks
đź§© The Challenge
You’ve got an application that should be talking to a remote service, but you’re getting connection timeouts for no apparent reason. You know your local iptables rules are a complete mess of legacy garbage, but you can’t figure out which specific chain is nuking your packets.
đź’ˇ The Fix
Instead of guessing or tearing down your firewall, just hook into the raw trace facility to watch the kernel make its decisions in real time. It’s like having a debugger for your network rules.
nft add rule ip filter output tcp dport 80 meta nftrace set 1
nft monitor trace
⚙️ Why It Works
Setting the nftrace bit marks those specific packets so the kernel sends metadata about every single rule match to a monitor buffer. You’re effectively forcing the firewall to narrate exactly why it decided to drop your traffic.
🚀 Pro-Tip: Don’t forget to delete that trace rule when you’re done, or your kernel log will fill up faster than you can blink.
Linux Tips & Tricks | © ngelinux.com | 9/14/2026
