diff --git a/ipv4-filter.nft b/ipv4-filter.nft new file mode 100644 index 0000000..214211f --- /dev/null +++ b/ipv4-filter.nft @@ -0,0 +1,5 @@ +table filter { + chain input { type filter hook input priority 0;policy drop;} + chain forward { type filter hook forward priority 0; } + chain output { type filter hook output priority 0; } +} diff --git a/ipv6-filter.nft b/ipv6-filter.nft new file mode 100644 index 0000000..225d93b --- /dev/null +++ b/ipv6-filter.nft @@ -0,0 +1,5 @@ +table ip6 filter { + chain input { type filter hook input priority 0; drop;} + chain forward { type filter hook forward priority 0; drop;} + chain output { type filter hook output priority 0; drop; } +}