I've been writing iptables rules to categorise packets based on the number of bytes transferred on their connections (i.e. using -m connbytes
), but these rules don't work properly. When I look at the connections in /proc/net/nf_conntrack
there seems to be something odd happening - nearly all of the RX/TX packet and byte counters are zero, even for connections that I know for sure have sent and received data.
In addition, I have tried starting a large download and watching the counters, and they appear to get reset to zero regularly. For example, when downloading a 1GB test file from here:
https://www.thinkbroadband.com/download
I see the counters for the connection getting reset to zero at least four times during the forty or so seconds it takes to download the file. Perhaps this regular resetting explains why nearly all the counters are zero? In any case, this behaviour stops my iptables rules from working correctly, so it's a significant problem for me.
Does anyone know what is going on? It's quite possible that I'm missing something and I'm happy to be set straight.
I'm using OpenWRT 19.07.1 on x86_64.