firewall/ipv4-filter.nft
2024-09-27 23:41:07 -06:00

22 lines
678 B
Plaintext

table filter {
set http_ratelimit { type ipv4_addr; timeout 1s; flags dynamic; }
chain input { type filter hook input priority 0;policy drop;}
chain forward { type filter hook forward priority 0;
iifname wg0 accept;
iifname home accept;
iifname eno1 accept;
ct status dnat accept;
}
chain output { type filter hook output priority 0; }
}
table nat {
chain prerouting { type nat hook prerouting priority -100; policy accept;}
chain postrouting { type nat hook postrouting priority 100;
iifname wg0 oifname eno1 masquerade;
iifname home oifname eno1 masquerade;
iifname eno1 oifname wg0 masquerade;
iifname eno1 oifname home masquerade;
}
}