From 0bfb4903b649f70fbbffd2ec57bfe5114b612685 Mon Sep 17 00:00:00 2001 From: Gregor Kleen Date: Thu, 13 Jan 2022 23:30:46 +0100 Subject: vidhar: ... --- hosts/vidhar/network/ruleset.nft | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) (limited to 'hosts') diff --git a/hosts/vidhar/network/ruleset.nft b/hosts/vidhar/network/ruleset.nft index c4c2fbe6..901ecb4f 100644 --- a/hosts/vidhar/network/ruleset.nft +++ b/hosts/vidhar/network/ruleset.nft @@ -248,11 +248,28 @@ table bridge filter { policy drop + log level debug prefix "bridge forward: " + + ct state invalid log level debug prefix "drop invalid forward: " counter name invalid-fw drop iifname "wifibh01.lan" counter name wifibh-fw accept iifname "eno2.lan" counter name lan-fw accept } + + chain input { + type filter hook input priority filter + policy accept + + log level debug prefix "bridge input: " + } + + chain output { + type filter hook output priority filter + policy accept + + log level debug prefix "bridge output: " + } } table ip nat { -- cgit v1.2.3