更新 Nftables 规则

This commit is contained in:
CallMeR
2024-09-27 14:30:48 +08:00
parent 4bf1e1d523
commit 999a06f938
+12 -8
View File
@@ -24,25 +24,24 @@ table inet router {
chain input {
type filter hook input priority filter; policy drop;
ct state established,related accept comment "defconf: handle inbound flows"
iif "lo" accept comment "defconf: accept traffic from loopback"
ct state vmap { established : accept, related : accept } comment "defconf: handle inbound flows"
ct state new meta l4proto tcp counter jump syn_flood comment "defconf: rate limit new TCP connections"
ct state new meta l4proto tcp jump syn_flood comment "defconf: rate limit new TCP connections"
iifname "eth0" jump input_lan comment "defconf: handle LAN IPv4 / IPv6 input traffic"
iifname "tailscale0" counter jump input_tailscale comment "tsconf: handle TS IPv4 / IPv6 input traffic"
}
chain forward {
type filter hook forward priority filter; policy drop;
ct state established,related flow add @ft comment "defconf: track forwarded flows"
ct state vmap { established : accept, related : accept } comment "defconf: handle forwarded flows"
ct state established,related goto handle_offload comment "defconf: handle forwarded flows"
iifname "eth0" jump forward_lan comment "defconf: handle LAN IPv4 / IPv6 forward traffic"
iifname "tailscale0" counter jump forward_tailscale comment "tsconf: handle TS IPv4 / IPv6 forward traffic"
}
chain output {
type filter hook output priority filter; policy accept;
ct state established,related accept comment "defconf: handle outbound flows"
oif "lo" accept comment "defconf: accept traffic towards loopback"
ct state vmap { established : accept, related : accept } comment "defconf: handle outbound flows"
oifname "eth0" jump output_lan comment "defconf: handle LAN IPv4 / IPv6 output traffic"
oifname "tailscale0" counter jump output_tailscale comment "tsconf: handle TS IPv4 / IPv6 output traffic"
}
@@ -58,14 +57,19 @@ table inet router {
counter drop comment "defconf: drop excess new TCP connections"
}
chain handle_offload {
flow add @ft accept comment "defconf: track forwarded flows"
accept
}
chain input_lan {
ct status dnat counter accept comment "lanconf: accept port redirect"
ct status dnat accept comment "lanconf: accept port redirect"
jump accept_from_lan
}
chain forward_lan {
jump accept_to_tailscale comment "tsconf: accept LAN to TS forward"
ct status dnat counter accept comment "lanconf: accept port forward"
ct status dnat accept comment "lanconf: accept port forward"
jump accept_to_lan
}
@@ -77,7 +81,7 @@ table inet router {
}
chain accept_from_lan {
iifname "eth0" counter accept comment "defconf: accept LAN IPv4 / IPv6 traffic"
iifname "eth0" accept comment "defconf: accept LAN IPv4 / IPv6 traffic"
}
chain accept_to_lan {