Block all input packets destinate to blackhole set by default.
This commit is contained in:
		
							parent
							
								
									043bc55dcb
								
							
						
					
					
						commit
						84fd89f6e6
					
				|  | @ -69,6 +69,8 @@ nft_input_default_rules: | ||||||
|     - type filter hook input priority 0; policy drop; |     - type filter hook input priority 0; policy drop; | ||||||
|   005 global: |   005 global: | ||||||
|     - jump global |     - jump global | ||||||
|  |   010 drop unwanted: | ||||||
|  |     - ip daddr @blackhole counter drop | ||||||
| nft_input_group_rules: {} | nft_input_group_rules: {} | ||||||
| nft_input_host_rules: {} | nft_input_host_rules: {} | ||||||
| 
 | 
 | ||||||
|  | @ -130,6 +132,7 @@ table inet firewall { | ||||||
| 	chain input { | 	chain input { | ||||||
| 		type filter hook input priority 0; policy drop; | 		type filter hook input priority 0; policy drop; | ||||||
| 		jump global | 		jump global | ||||||
|  | 		ip daddr @blackhole counter packets 3 bytes 204 drop | ||||||
| 	} | 	} | ||||||
| 
 | 
 | ||||||
| 	chain output { | 	chain output { | ||||||
|  |  | ||||||
|  | @ -27,6 +27,8 @@ nft_input_default_rules: | ||||||
|     - type filter hook input priority 0; policy drop; |     - type filter hook input priority 0; policy drop; | ||||||
|   005 global: |   005 global: | ||||||
|     - jump global |     - jump global | ||||||
|  |   010 drop unwanted: | ||||||
|  |     - ip daddr @blackhole counter drop | ||||||
| nft_input_group_rules: {} | nft_input_group_rules: {} | ||||||
| nft_input_host_rules: {} | nft_input_host_rules: {} | ||||||
| 
 | 
 | ||||||
|  |  | ||||||
		Loading…
	
		Reference in New Issue