Iptables: LOG target not working in LXD containers

If you're using LXD, you may be surprised that you're not getting packets logged with iptables' LOG target. Or, not really surprised - since the LOG target is kernel logging, and LXD containers are pretty much limited when it comes to accessing various kernel functions, for security reason.

A workaround is to use NFLOG target and ulogd2:


So if your rules looked like below:


Then just change LOG target to NFLOG:

Then, ulogd2 will write the logs to /var/log/ulog/ directory, i.e.:

Also, please note that ULOG target was deprecated (you'll still find a lot of info about it) - you need to use NFLOG instead.

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to Lxadm.com.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.