summary refs log tree commit diff
path: root/steel-nftables.conf
blob: e5d379cc69841bf4409941eb339d7474eded5259 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
table ip filter {
  chain input {
    # Drop all traffic by default.
    type filter hook input priority 0; policy drop;
    # Allow traffic from established connections.
    ct state vmap { established: accept, related: accept, invalid: drop }
    # Allow loopback traffic.
    iifname lo accept
    # Allow 8080 for occasional darkhttpd use.
    tcp dport 8080 accept
  }
}