I'm quite new to OpenWrt so I hope my question will be clear
I'm working with OpenWrt 23.05.2 (r23630-842932a63d) and I set up a port forwarding rule but it doesn't seem to work... So I would like to log the connection attempt but I don't know how to do it...
I tried to add a nftables rule but I don't know where are the logs... I couldn't find any information on the internet... Here is the the result I get with nft list ruleset
table inet fw4 {
chain input {
type filter hook input priority filter; policy drop;
iifname "lo" accept comment "!fw4: Accept traffic from loopback"
ct state established,related accept comment "!fw4: Allow inbound established and related flows"
tcp flags syn / fin,syn,rst,ack jump syn_flood comment "!fw4: Rate limit TCP syn packets"
iifname "br-lan" jump input_lan comment "!fw4: Handle lan IPv4/IPv6 input traffic"
iifname { "wan", "pppoe-wan" } jump input_wan comment "!fw4: Handle wan IPv4/IPv6 input traffic"
jump handle_reject
tcp dport 8123 ct state new log prefix "New Home Assistant connection: "
}
...
}
The relevant line here is the last obviously ^^ I found that command here
Be careful about this feature since there is potential for some serious logread spam! I think this feature is mostly used for temporary debugging to check things are working properly (albeit there may also be some uses when permanently enabled logging is desired).
You can add option log 'Test log prefix' to your redirect rule in /etc/config/firewall to enable the logging of that rule with that log prefix (or any other helpful prefix.
Removing the list src_mac solved the connection problem, thanks !
But I added the mac address to restrict the connection to some devices... So how do I achieve that ?
We are talking about layer 3 traffic so that cannot work with MAC address.
It can work with ip address, but you are probably not using your phone from a fixed address so not possible.
Note I do not know to what you are port forwarding to, but consider setting up WireGuard to connect to your home which could be the safer option