2023-11-22 08:26:10 +01:00
|
|
|
#!/usr/sbin/nft -f
|
|
|
|
|
|
|
|
flush ruleset
|
|
|
|
|
|
|
|
table inet filter {
|
|
|
|
chain input {
|
|
|
|
type filter hook input priority 0; policy drop;
|
|
|
|
|
|
|
|
iif lo accept
|
2023-11-29 08:32:08 +01:00
|
|
|
|
2023-11-22 08:26:10 +01:00
|
|
|
ct state invalid drop
|
2023-11-29 08:32:08 +01:00
|
|
|
ct state { established, related } accept
|
2023-11-22 08:26:10 +01:00
|
|
|
|
2023-12-01 13:33:10 +01:00
|
|
|
# HTTP & Syncthing Relay
|
|
|
|
tcp dport { http, https, 5432, 22000 } limit rate 5/second accept
|
|
|
|
udp dport 22000 limit rate 5/second accept
|
2023-11-29 20:00:29 +01:00
|
|
|
|
2023-11-22 08:26:10 +01:00
|
|
|
# SSH
|
2023-11-29 08:32:08 +01:00
|
|
|
tcp dport 995 limit rate 15/minute accept
|
2023-11-22 08:26:10 +01:00
|
|
|
|
2023-12-08 12:22:33 +01:00
|
|
|
# TURN
|
|
|
|
tcp dport { 3478, 5349 } limit rate 5/second accept
|
2024-02-15 11:24:39 +01:00
|
|
|
udp dport { 3478, 5349, 49152-49172 } limit rate 5/second accept
|
2023-12-08 12:22:33 +01:00
|
|
|
|
2023-11-29 20:00:29 +01:00
|
|
|
# Allow ICMP
|
|
|
|
meta l4proto icmp limit rate 1/second accept
|
|
|
|
meta l4proto ipv6-icmp limit rate 1/second accept
|
2023-11-22 08:26:10 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
chain forward {
|
|
|
|
type filter hook forward priority 0; policy accept;
|
|
|
|
}
|
|
|
|
|
|
|
|
chain output {
|
|
|
|
type filter hook output priority 0; policy accept;
|
|
|
|
}
|
|
|
|
}
|