updated nftables state
This commit is contained in:
parent
631f81b740
commit
538e5e9b8d
@ -38,7 +38,7 @@ add chain ip6 filter6 output { type filter hook output priority 0; policy accept
|
|||||||
add rule ip6 filter6 input iifname lo counter accept
|
add rule ip6 filter6 input iifname lo counter accept
|
||||||
add rule ip6 filter6 input iifname tun* counter accept
|
add rule ip6 filter6 input iifname tun* counter accept
|
||||||
add rule ip6 filter6 input ct state related,established counter accept
|
add rule ip6 filter6 input ct state related,established counter accept
|
||||||
add rule ip6 filter6 input icmpv6 type { nd-neighbor-solicit, nd-router-advert, nd-neighbor-advert } accept
|
add rule ip6 filter6 input icmpv6 type {destination-unreachable, packet-too-big, time-exceeded, echo-request, echo-reply, mld-listener-query, mld-listener-report, mld-listener-reduction, nd-router-solicit, nd-router-advert, nd-neighbor-solicit, nd-neighbor-advert, nd-redirect, parameter-problem, router-renumbering} accept
|
||||||
{%- for key, value in net.ipv6_networks.items() %}
|
{%- for key, value in net.ipv6_networks.items() %}
|
||||||
add rule ip6 filter6 input ip6 saddr {{ value.ip }}/{{ value.mask }} ct state established,new counter accept
|
add rule ip6 filter6 input ip6 saddr {{ value.ip }}/{{ value.mask }} ct state established,new counter accept
|
||||||
{%- endfor %}
|
{%- endfor %}
|
||||||
|
Loading…
Reference in New Issue
Block a user