X-Git-Url: https://git.ao2.it/config/nftables.git/blobdiff_plain/d684d1e527c3554ae88b01d215d3a07d7606cbad..a8a3ce6b575f8de21d2b325fbcb93e29ea51235a:/nftables-workstation.nft diff --git a/nftables-workstation.nft b/nftables-workstation.nft index fd227f5..ecfb200 100644 --- a/nftables-workstation.nft +++ b/nftables-workstation.nft @@ -39,7 +39,8 @@ table inet filter { } chain input { - type filter hook input priority 0; + type filter hook input priority 0 + policy drop ct state established,related accept ct state invalid drop @@ -123,13 +124,17 @@ table inet filter { } chain forward { - type filter hook forward priority 0; + type filter hook forward priority 0 + policy drop + limit rate 3/minute burst 10 packets log prefix "[FORWARD]: " counter reject } chain output { - type filter hook output priority 0; + type filter hook output priority 0 + policy drop + counter accept } }