iptables_exporter icon indicating copy to clipboard operation
iptables_exporter copied to clipboard

default input policy is not realized

Open toralf opened this issue 2 years ago • 1 comments

I do have

  iptables -P INPUT  ${DEFAULT_POLICY_INPUT:-DROP}

here https://github.com/toralf/torutils/blob/main/ipv4-rules.sh#L6

and verified it

Chain INPUT (policy DROP 110 packets, 6110 bytes)
 pkts bytes target     prot opt in     out     source               destination

but I do get from the exporter:

 # curl -s localhost:9455/metrics  | grep -i policy | grep INPUT
ip6tables_chain_bytes_total{chain="INPUT",policy="ACCEPT",table="filter"} 0
ip6tables_chain_packets_total{chain="INPUT",policy="ACCEPT",table="filter"} 0
iptables_chain_bytes_total{chain="INPUT",policy="ACCEPT",table="filter"} 5294
iptables_chain_packets_total{chain="INPUT",policy="ACCEPT",table="filter"} 90

I had similar issue with the rule values too.

toralf avatar Mar 12 '23 20:03 toralf