Netfilter Sysfs variables

/proc/sys/net/netfilter/* Variables:

nf_log_all_netns - BOOLEAN
  • 0 - disabled (default)
  • not 0 - enabled

By default, only init_net namespace can log packets into kernel logwith LOG target; this aims to prevent containers from flooding hostkernel log. If enabled, this target also works in other networknamespaces. This variable is only accessible from init_net.