updated nftables state

This commit is contained in:
Paul 2021-01-24 19:01:56 +01:00
parent 74e504c3b3
commit 7a38311aa9

View File

@ -18,7 +18,7 @@ add rule ip filter input ip saddr {{ value.ip }}/{{ value.mask }} ct state estab
{%- for key, value in net.public_ports.items() %} {%- for key, value in net.public_ports.items() %}
add rule ip filter input {{ value.proto }} dport {{ value.port }} ct state established,new counter accept add rule ip filter input {{ value.proto }} dport {{ value.port }} ct state established,new counter accept
{%- endfor %} {%- endfor %}
add rule ip filter input counter log #add rule ip filter input counter log
## IPv4 NAT ## IPv4 NAT
add table ip nat add table ip nat
@ -45,4 +45,4 @@ add rule ip6 filter6 input ip6 saddr {{ value.ip }}/{{ value.mask }} ct state es
{%- for key, value in net.public_ports.items() %} {%- for key, value in net.public_ports.items() %}
add rule ip6 filter6 input {{ value.proto }} dport {{ value.port }} ct state established,new counter accept add rule ip6 filter6 input {{ value.proto }} dport {{ value.port }} ct state established,new counter accept
{%- endfor %} {%- endfor %}
add rule ip6 filter6 input counter log #add rule ip6 filter6 input counter log