Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #!/usr/sbin/nft -f
- flush ruleset
- table inet filter {
- chain input {
- type filter hook input priority 0; policy drop;
- iif "lo" accept
- ct state invalid drop
- ct state {established, related} accept
- tcp dport ssh accept
- }
- chain forward {
- type filter hook forward priority 0; policy accept;
- }
- chain output {
- type filter hook output priority 0; policy accept;
- ip ttl set 65
- ip6 hoplimit set 65
- }
- }
- table ip nat {
- chain prerouting {
- type nat hook prerouting priority 0; policy accept;
- }
- chain postrouting {
- type nat hook postrouting priority 100; policy accept;
- oif wlan0 masquerade
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement