summaryrefslogtreecommitdiff
path: root/hosts/vidhar
diff options
context:
space:
mode:
authorGregor Kleen <gkleen@yggdrasil.li>2021-12-13 21:41:10 +0100
committerGregor Kleen <gkleen@yggdrasil.li>2021-12-13 21:41:10 +0100
commitd8922d513a35bf5e7d75ea0d812d7dcdb6f2c395 (patch)
tree5db2e4ca378b260ae09c9a57971e77bc425e4cb1 /hosts/vidhar
parent3dd95b2119e7ddf3ac68aa5a744076e2daa4e99f (diff)
downloadnixos-d8922d513a35bf5e7d75ea0d812d7dcdb6f2c395.tar
nixos-d8922d513a35bf5e7d75ea0d812d7dcdb6f2c395.tar.gz
nixos-d8922d513a35bf5e7d75ea0d812d7dcdb6f2c395.tar.bz2
nixos-d8922d513a35bf5e7d75ea0d812d7dcdb6f2c395.tar.xz
nixos-d8922d513a35bf5e7d75ea0d812d7dcdb6f2c395.zip
nftables: ...
Diffstat (limited to 'hosts/vidhar')
-rw-r--r--hosts/vidhar/ruleset.nft4
1 files changed, 2 insertions, 2 deletions
diff --git a/hosts/vidhar/ruleset.nft b/hosts/vidhar/ruleset.nft
index 3d4d1bb0..ca0e5716 100644
--- a/hosts/vidhar/ruleset.nft
+++ b/hosts/vidhar/ruleset.nft
@@ -88,14 +88,14 @@ table inet filter {
88 iifname != dsl meta l4proto $icmp_protos limit name lim_icmp_local counter drop 88 iifname != dsl meta l4proto $icmp_protos limit name lim_icmp_local counter drop
89 meta l4proto $icmp_protos counter accept 89 meta l4proto $icmp_protos counter accept
90 90
91 ct state {established, related} counter accept
92
93 tcp dport 22 counter accept 91 tcp dport 22 counter accept
94 meta protocol ip udp dport 51820 counter accept 92 meta protocol ip udp dport 51820 counter accept
95 udp dport 60000-61000 counter accept 93 udp dport 60000-61000 counter accept
96 94
97 iifname dsl meta protocol ip6 udp dport 546 udp sport 547 counter accept 95 iifname dsl meta protocol ip6 udp dport 546 udp sport 547 counter accept
98 96
97 ct state {established, related} counter accept
98
99 99
100 limit name lim_reject log prefix "drop input: " counter drop 100 limit name lim_reject log prefix "drop input: " counter drop
101 log prefix "reject input: " counter 101 log prefix "reject input: " counter