chain input {
type filter hook input priority 0
+ policy drop
ct state established,related accept
ct state invalid drop
chain forward {
type filter hook forward priority 0
+ policy drop
+
limit rate 3/minute burst 10 packets log prefix "[FORWARD]: "
counter reject
}
chain output {
type filter hook output priority 0
+ policy drop
+
counter accept
}
}