diff --git a/src/debian/debian_ts_nftables.conf b/src/debian/debian_ts_nftables.conf index c00146d..cd6790a 100644 --- a/src/debian/debian_ts_nftables.conf +++ b/src/debian/debian_ts_nftables.conf @@ -41,7 +41,7 @@ table inet router { chain output { type filter hook output priority filter; policy accept; - ct state vmap { established : accept, related : accept, invalid : drop } comment "defconf: handle outbound flows" + ct state established,related accept comment "defconf: handle outbound flows" oif "lo" accept comment "defconf: accept traffic towards loopback" oifname "eth0" jump output_lan comment "defconf: handle LAN IPv4 / IPv6 output traffic" oifname "tailscale0" jump output_tailscale comment "tsconf: handle TS IPv4 / IPv6 output traffic" @@ -77,6 +77,7 @@ table inet router { } chain accept_to_lan { + meta nfproto ipv4 oifname "eth0" ct state invalid counter drop comment "defconf: prevent LAN NATv4 leakage" oifname "eth0" accept comment "defconf: accept LAN IPv4 / IPv6 traffic" }