1
0
Fork 0

.config/nftables.conf: update

main
urosm 2024-06-12 00:47:39 +02:00
parent e27c5cfe97
commit f4aba20d0b
1 changed files with 11 additions and 9 deletions

View File

@ -3,13 +3,15 @@
flush ruleset
table inet filter {
chain input {
type filter hook input priority filter; policy drop;
# accept any localhost traffic
iif lo accept
# accept traffic originated from us
ct state established,related accept
# accept neighbour discovery otherwise connectivity breaks
icmpv6 type { nd-neighbor-solicit, nd-router-advert, nd-neighbor-advert } accept
}
chain input {
type filter hook input priority filter; policy drop;
iif lo accept comment "Accept localhost traffic"
ct state invalid drop comment "Drop invalid connections"
ct state established,related accept comment "Accept established and related connections"
meta l4proto { icmp, ipv6-icmp } accept comment "Accept ICMP/ICMPv6 traffic"
ip protocol igmp accept comment "Accept IGMP traffic"
udp dport mdns accept comment "Accept mDNS"
}
}