Why the packets and bytes counter of ipset is not incrementing even after iptables rule matches?

Solution In Progress - Updated -

Issue

  • Ipset packets & bytes counter is not incrementing after the iptables rule matches.
  • Why the iptables extension --bytes-gt is not working?
  • Why the incoming packets are not getting dropped after reaching the value in --bytes-gt in an iptables rule with drop target?

Environment

  • Red Hat Enterprise Linux 7.6 and newer
  • Red Hat Enterprise Linux 8(RHEL 8)
  • Ipset
  • Iptables

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content