Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #!/usr/sbin/nft -f
- flush ruleset
- table ip nat {
- chain postrouting {
- type nat hook postrouting priority srcnat; policy accept;
- oifname "wlan0" meta cgroup 1114129 counter masquerade
- }
- }
- table ip mangle {
- chain markit {
- type route hook output priority filter; policy accept;
- meta cgroup 1114129 counter meta mark set 0x0000000b
- }
- }
- table ip killswitch {
- chain output {
- type filter hook output priority filter; policy accept;
- oifname "lo" counter accept
- oifname "tun0" counter accept
- meta cgroup 1114129 counter accept
- counter reject with icmp type admin-prohibited
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement