diff options
Diffstat (limited to 'hosts/skadhi/networking')
| -rw-r--r-- | hosts/skadhi/networking/ruleset.nft | 16 |
1 files changed, 15 insertions, 1 deletions
diff --git a/hosts/skadhi/networking/ruleset.nft b/hosts/skadhi/networking/ruleset.nft index 62339f69..94e21b10 100644 --- a/hosts/skadhi/networking/ruleset.nft +++ b/hosts/skadhi/networking/ruleset.nft | |||
| @@ -113,7 +113,21 @@ table inet filter { | |||
| 113 | ct state new counter name reject-icmp-fw reject | 113 | ct state new counter name reject-icmp-fw reject |
| 114 | } | 114 | } |
| 115 | 115 | ||
| 116 | chain input_tmp {} | 116 | ct helper ftp-standard { |
| 117 | type "ftp" protocol tcp | ||
| 118 | } | ||
| 119 | chain input_pr_tmp { | ||
| 120 | # tcp dport 2121 ct helper set "ftp-standard" | ||
| 121 | } | ||
| 122 | chain input_pr { | ||
| 123 | type filter hook prerouting priority 0 | ||
| 124 | |||
| 125 | jump input_pr_tmp | ||
| 126 | } | ||
| 127 | |||
| 128 | chain input_tmp { | ||
| 129 | # tcp dport 2121 accept | ||
| 130 | } | ||
| 117 | chain input { | 131 | chain input { |
| 118 | type filter hook input priority filter | 132 | type filter hook input priority filter |
| 119 | policy drop | 133 | policy drop |
