Can firewalld NOT log INVALID-state drops when configured with --set-log-denied?
Issue
- Can firewalld NOT log INVALID-state drops when configured with
--set-log-denied? - firewalld with
--set-log-denied=unicastalso logs packets which are in conntrackINVALIDstate, which makes additional unwanted logs. Can this be changed?
Environment
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux 8
firewalldfirewall withnft(nftables) backend- Firewall option
--set-log-deniedset to one of the settings notoff
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.