Page MenuHomeVyOS Platform

Add nftrace-story as a CLI command
Open, LowPublicFEATURE REQUEST

Description

Summary

Add nftrace-story as a CLI command.

Perhaps something like "show trace nft-story", "show debug nft-story" or such?

"show trace" or "show debug" would then contain other handy debugging tools.

Would make it easier to interpret what happens within nftables for a certain flow.

Use case

Best explained at forum thread and the github itself.

Example output:

** Trace 9faeedfc

*** Story
- tcp 192.168.0.50:53158 → 34.117.59.81:80 arrived on interface "eth1".
- Routing selected egress interface "eth0" (forwarding path).
- TTL was decremented by 1 at L253 (typical for forwarding).
- It was last observed near the FORWARD hook (L523).
- Final disposition: ACCEPT (L523).
- NAT detected:
  - L271: Masquerade
- MSS rewrite detected:
  - L259: maxseg size set rt mtu
- Tables visited:
  - `trace`: prerouting
  - `vyos_conntrack`: PREROUTING, VYOS_CT_IGNORE, FW_CONNTRACK, NAT_CONNTRACK, PREROUTING_HELPER, VYOS_CT_HELPER
  - `vyos_filter`: VYOS_PREROUTING_raw, VYOS_FORWARD_filter
  - `vrf_zones`: vrf_zones_ct_in
  - `raw`: VYOS_PREROUTING_HOOK, vyos_rpfilter, vyos_global_rpfilter, VYOS_TCP_MSS
  - `vyos_static_nat`: PREROUTING, POSTROUTING
  - `vyos_nat`: PREROUTING, VYOS_PRE_DNAT_HOOK, POSTROUTING, VYOS_PRE_SNAT_HOOK
  - `mangle`: FORWARD
  - `nat`: VYOS_PRE_SNAT_HOOK
- Rules hit:
  - `trace`.`prerouting` L217: meta nftrace set 1 (verdict continue, x3)
  - `vyos_conntrack`.`PREROUTING` L221: counter packets 2178 bytes 287508 jump VYOS_CT_IGNORE (verdict jump VYOS_CT_IGNORE, x3)
  - `vyos_conntrack`.`PREROUTING` L223: counter packets 2178 bytes 287508 jump FW_CONNTRACK (verdict jump FW_CONNTRACK, x3)
  - `vyos_conntrack`.`PREROUTING` L225: counter packets 2178 bytes 287508 jump NAT_CONNTRACK (verdict jump NAT_CONNTRACK, x3)
  - `vyos_conntrack`.`NAT_CONNTRACK` L226: accept (verdict accept, x3)
  - `vyos_filter`.`VYOS_PREROUTING_raw` L228: counter packets 19572 bytes 5868890 accept comment "PRE-raw default-action accept" (verdict accept, x3)
  - `raw`.`vyos_rpfilter` L236: counter packets 19979 bytes 5901810 jump vyos_global_rpfilter (verdict jump vyos_global_rpfilter, x3)
  - `vyos_nat`.`PREROUTING` L244: counter packets 14 bytes 1360 jump VYOS_PRE_DNAT_HOOK (verdict jump VYOS_PRE_DNAT_HOOK)
  - `vyos_conntrack`.`PREROUTING_HELPER` L249: counter packets 2178 bytes 287508 jump VYOS_CT_HELPER (verdict jump VYOS_CT_HELPER, x3)
  - `vyos_filter`.`VYOS_FORWARD_filter` L257: counter packets 1356 bytes 110874 accept comment "FWD-filter default-action accept" (verdict accept, x3)
  - `raw`.`VYOS_TCP_MSS` L259: oifname "eth0" tcp flags syn _ syn, rst tcp option maxseg size set rt mtu (verdict continue)
  - `vyos_nat`.`POSTROUTING` L269: counter packets 13 bytes 1060 jump VYOS_PRE_SNAT_HOOK (verdict jump VYOS_PRE_SNAT_HOOK)
  - `vyos_nat`.`POSTROUTING` L271: oifname "eth0" ip saddr 192.168.0.0_16 counter packets 9 bytes 568 masquerade comment "SRC-NAT-10" (verdict accept)

- ** Flow: tcp 192.168.0.50:53158 → 34.117.59.81:80
- ** Ingress: received on "eth1"
- ** Egress: forwarded out "eth0"

Note: I had to slightly modify the example to be able to post it here at vyos.dev since frontslash and * seems to be disliked when quoting (or there is some WAF blocking stuff).

Additional information

https://forum.vyos.io/t/utility-nftrace-storyteller/17309

https://github.com/l0crian1/nftrace-story

Details

Version
-
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Feature (new functionality)
Forum thread
https://forum.vyos.io/t/utility-nftrace-storyteller/17309