Stop staring at raw packet drops when your firewall is killing traffic
Networking & Firewall (Ss/Netstat/Iptables/Nftables/Curl)
Stop staring at raw packet drops when your firewall is killing traffic
🧩 The Challenge
Dealing with a service that refuses to talk to its database is miserable when you can’t tell if the traffic is getting nuked by iptables or just swallowed by a black hole. I spent half a Saturday tracing a rogue DROP rule once because I couldn’t figure out where the packet was dying.
💡 The Fix
Use the trace feature in nftables to watch individual packets traverse your chains in real-time. It’s like turning the lights on in a pitch-black server room.
nft monitor trace
nft add rule ip filter output tcp dport 5432 meta nftrace set 1
⚙️ Why It Works
Setting the nftrace bit on a specific rule tells the kernel to send metadata about that packet to the monitor command. Watching this output shows you exactly which chain, rule, and verdict hits your traffic.
🚀 Pro-Tip: Don’t forget to delete that rule when you’re done, or you’ll be flooding your logs and killing your CPU performance.
Linux Tips & Tricks | © ngelinux.com | 8/30/2026
