summaryrefslogtreecommitdiff
path: root/hosts/vidhar/printing/ruleset.nft
diff options
context:
space:
mode:
Diffstat (limited to 'hosts/vidhar/printing/ruleset.nft')
-rw-r--r--hosts/vidhar/printing/ruleset.nft11
1 files changed, 6 insertions, 5 deletions
diff --git a/hosts/vidhar/printing/ruleset.nft b/hosts/vidhar/printing/ruleset.nft
index c3027567..e47256c3 100644
--- a/hosts/vidhar/printing/ruleset.nft
+++ b/hosts/vidhar/printing/ruleset.nft
@@ -44,6 +44,7 @@ table inet filter {
44 counter fw-printer {} 44 counter fw-printer {}
45 counter fw-host {} 45 counter fw-host {}
46 46
47 counter icmp-fw {}
47 counter icmp-ratelimit-fw {} 48 counter icmp-ratelimit-fw {}
48 49
49 counter reject-ratelimit-fw {} 50 counter reject-ratelimit-fw {}
@@ -97,9 +98,9 @@ table inet filter {
97 meta l4proto $icmp_protos counter name icmp-fw accept 98 meta l4proto $icmp_protos counter name icmp-fw accept
98 99
99 100
100 iifname printer oifname eth0 ip daddr 10.141.4.0 meta l4proto . th dport { tcp . 53, udp . 53, udp . 123 } counter fw-printer accept 101 iifname printer oifname eth0 ip daddr 10.141.5.0 meta l4proto . th dport { tcp . 53, udp . 53, udp . 123 } counter name fw-printer accept
101 iifname printer oifname eth0 ip6 daddr 2a03:4000:52:ada:4:: meta l4proto . th dport { tcp . 53, udp . 53, udp . 123 } counter fw-printer accept 102 iifname printer oifname eth0 ip6 daddr 2a03:4000:52:ada:5:: meta l4proto . th dport { tcp . 53, udp . 53, udp . 123 } counter name fw-printer accept
102 iifname eth0 oifname printer counter fw-host accept 103 iifname eth0 oifname printer counter name fw-host accept
103 104
104 105
105 limit name lim_reject log level debug prefix "drop forward: " counter name reject-ratelimit-fw drop 106 limit name lim_reject log level debug prefix "drop forward: " counter name reject-ratelimit-fw drop
@@ -127,8 +128,8 @@ table inet filter {
127 meta l4proto $icmp_protos counter name icmp-rx accept 128 meta l4proto $icmp_protos counter name icmp-rx accept
128 129
129 130
130 ip6 saddr 2a03:4000:52:ada:4:: tcp dport 631 counter name cups-rx accept 131 ip6 saddr 2a03:4000:52:ada:5:: tcp dport 631 counter name cups-rx accept
131 ip saddr 10.141.4.0 tcp dport 631 counter name cups-rx accept 132 ip saddr 10.141.5.0 tcp dport 631 counter name cups-rx accept
132 133
133 ct state {established, related} counter name established-rx accept 134 ct state {established, related} counter name established-rx accept
134 135