Site icon New Generation Enterprise Linux

Stop staring at raw packet drops when your firewall is killing traffic

Networking & Firewall (Ss/Netstat/Iptables/Nftables/Curl)

Stop staring at raw packet drops when your firewall is killing traffic

đź§© The Challenge

Dealing with a service that refuses to talk to its database is miserable when you can’t tell if the traffic is getting nuked by iptables or just swallowed by a black hole. I spent half a Saturday tracing a rogue DROP rule once because I couldn’t figure out where the packet was dying.

đź’ˇ The Fix

Use the trace feature in nftables to watch individual packets traverse your chains in real-time. It’s like turning the lights on in a pitch-black server room.

nft monitor trace
nft add rule ip filter output tcp dport 5432 meta nftrace set 1

⚙️ Why It Works

Setting the nftrace bit on a specific rule tells the kernel to send metadata about that packet to the monitor command. Watching this output shows you exactly which chain, rule, and verdict hits your traffic.

🚀 Pro-Tip: Don’t forget to delete that rule when you’re done, or you’ll be flooding your logs and killing your CPU performance.

Linux Tips & Tricks | © ngelinux.com | 8/30/2026

0 0 votes
Article Rating
Exit mobile version