updated nftables state
This commit is contained in:
parent
74e504c3b3
commit
7a38311aa9
@ -18,7 +18,7 @@ add rule ip filter input ip saddr {{ value.ip }}/{{ value.mask }} ct state estab
|
|||||||
{%- for key, value in net.public_ports.items() %}
|
{%- for key, value in net.public_ports.items() %}
|
||||||
add rule ip filter input {{ value.proto }} dport {{ value.port }} ct state established,new counter accept
|
add rule ip filter input {{ value.proto }} dport {{ value.port }} ct state established,new counter accept
|
||||||
{%- endfor %}
|
{%- endfor %}
|
||||||
add rule ip filter input counter log
|
#add rule ip filter input counter log
|
||||||
|
|
||||||
## IPv4 NAT
|
## IPv4 NAT
|
||||||
add table ip nat
|
add table ip nat
|
||||||
@ -45,4 +45,4 @@ add rule ip6 filter6 input ip6 saddr {{ value.ip }}/{{ value.mask }} ct state es
|
|||||||
{%- for key, value in net.public_ports.items() %}
|
{%- for key, value in net.public_ports.items() %}
|
||||||
add rule ip6 filter6 input {{ value.proto }} dport {{ value.port }} ct state established,new counter accept
|
add rule ip6 filter6 input {{ value.proto }} dport {{ value.port }} ct state established,new counter accept
|
||||||
{%- endfor %}
|
{%- endfor %}
|
||||||
add rule ip6 filter6 input counter log
|
#add rule ip6 filter6 input counter log
|
||||||
|
Loading…
Reference in New Issue
Block a user