Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- https://wiki.nftables.org/wiki-nftables/index.php/Quick_reference-nftables_in_10_minutes#Ip
- #Simple IP/IPv6 Firewall
- #!/usr/sbin/nft -f
- flush ruleset
- table inet filter {
- chain incomming {
- type filter hook input priority 0; policy drop
- # established/related connections
- ct state established,related accept log
- # loopback interface
- iifname lo accept comment "accept all incomming lo" log
- # icmp
- icmp type echo-request accept log
- # open tcp ports: sshd (22), httpd (80)
- tcp dport {ssh, http} accept log
- }
- }
- ~
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement