blob: e5d379cc69841bf4409941eb339d7474eded5259 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
|
table ip filter {
chain input {
# Drop all traffic by default.
type filter hook input priority 0; policy drop;
# Allow traffic from established connections.
ct state vmap { established: accept, related: accept, invalid: drop }
# Allow loopback traffic.
iifname lo accept
# Allow 8080 for occasional darkhttpd use.
tcp dport 8080 accept
}
}
|