Why the packets and bytes counter of ipset is not incrementing even after iptables rule matches?

Solution In Progress - Updated -

Issue

  • Ipset packets & bytes counter is not incrementing after the iptables rule matches.
  • Why the iptables extension --bytes-gt is not working?
  • Why the incoming packets are not getting dropped after reaching the value in --bytes-gt in an iptables rule with drop target?

Environment

  • Red Hat Enterprise Linux 7.6 and newer
  • Red Hat Enterprise Linux 8(RHEL 8)
  • Ipset
  • Iptables

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.

Current Customers and Partners

Log in for full access

Log In