1
0
Fork 0

.config/nftables.conf: add nftables config

main
urosm 2024-04-28 18:01:42 +02:00
parent 374cdf91bc
commit 02e32ae72f
1 changed files with 15 additions and 0 deletions

View File

@ -0,0 +1,15 @@
#!/usr/sbin/nft -f
flush ruleset
table inet filter {
chain input {
type filter hook input priority filter; policy drop;
# accept any localhost traffic
iif lo accept
# accept traffic originated from us
ct state established,related accept
# accept neighbour discovery otherwise connectivity breaks
icmpv6 type { nd-neighbor-solicit, nd-router-advert, nd-neighbor-advert } accept
}
}