type filter hook input priority 0
policy drop
- ct state established,related accept
- ct state invalid drop
- ct state new jump in-new
-
iif lo accept
ip protocol icmp icmp type {
# Allow IGMPv3 queries.
ip protocol igmp ip daddr 224.0.0.1 accept
+ # Stateful filtering for anything else.
+ ct state established,related accept
+ ct state invalid drop
+ ct state new jump in-new
+
# Silently drop other incoming broadcast and multicast traffic.
meta pkttype {broadcast, multicast} drop