From 65551ab77d6b6dbeca2e6b63de6ac3fd64ab5d61 Mon Sep 17 00:00:00 2001 From: coasteen Date: Wed, 5 Aug 2026 11:21:20 +0330 Subject: init --- etc/nftables.conf | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) create mode 100644 etc/nftables.conf (limited to 'etc/nftables.conf') diff --git a/etc/nftables.conf b/etc/nftables.conf new file mode 100644 index 0000000..8acb952 --- /dev/null +++ b/etc/nftables.conf @@ -0,0 +1,21 @@ +table inet filter { + chain input { + type filter hook input priority 0; policy drop; + iif lo accept + ct state established,related accept + iif enp4s0 accept + tcp dport 8443 iif enp3s0 accept + } + chain forward { + type filter hook forward priority 0; policy drop; + ct state established,related accept + iif enp4s0 oif enp3s0 accept + } +} + +table ip nat { + chain postrouting { + type nat hook postrouting priority 100; + oif enp3s0 masquerade + } +} -- cgit v1.2.3