#!/usr/sbin/nft -f # This configuration file is customized by fox, # Optimize nftables rules for local TS server. table inet router flush table inet router table inet router { # # Flowtable # flowtable ft { hook ingress priority filter; devices = { eth0 }; counter; } # # Filter rules # chain input { type filter hook input priority filter; policy drop; ct state established,related accept comment "defconf: handle inbound flows" iif "lo" accept comment "defconf: accept traffic from loopback" ct state new meta l4proto tcp jump syn_flood comment "defconf: rate limit new TCP connections" iifname "eth0" jump input_lan comment "defconf: handle LAN IPv4 / IPv6 input traffic" iifname "tailscale0" jump input_tailscale comment "tsconf: handle TS IPv4 / IPv6 input traffic" } chain forward { type filter hook forward priority filter; policy drop; ct state established,related goto handle_offload comment "defconf: handle forwarded flows" iifname "eth0" jump forward_lan comment "defconf: handle LAN IPv4 / IPv6 forward traffic" iifname "tailscale0" jump forward_tailscale comment "tsconf: handle TS IPv4 / IPv6 forward traffic" } chain output { type filter hook output priority filter; policy accept; ct state vmap { established : accept, related : accept, invalid : drop } comment "defconf: handle outbound flows" oif "lo" accept comment "defconf: accept traffic towards loopback" oifname "eth0" jump output_lan comment "defconf: handle LAN IPv4 / IPv6 output traffic" oifname "tailscale0" jump output_tailscale comment "tsconf: handle TS IPv4 / IPv6 output traffic" } chain syn_flood { limit rate 200/second burst 100 packets return comment "defconf: accept new TCP connections below rate-limit" counter drop comment "defconf: drop excess new TCP connections" } chain handle_offload { flow add @ft comment "defconf: track forwarded flows" accept } chain input_lan { ct status dnat accept comment "lanconf: accept port redirect" jump accept_from_lan } chain forward_lan { jump accept_to_tailscale comment "tsconf: accept LAN to TS forwarding" ct status dnat accept comment "lanconf: accept port forwards" jump accept_to_lan } chain output_lan { jump accept_to_lan } chain accept_from_lan { iifname "eth0" accept comment "defconf: accept LAN IPv4 / IPv6 traffic" } chain accept_to_lan { oifname "eth0" accept comment "defconf: accept LAN IPv4 / IPv6 traffic" } chain input_tailscale { jump accept_from_tailscale } chain forward_tailscale { jump accept_to_lan comment "tsconf: accept TS to LAN forwarding" jump accept_to_tailscale } chain output_tailscale { jump accept_to_tailscale } chain accept_from_tailscale { meta nfproto ipv4 iifname "tailscale0" counter accept comment "tsconf: accept TS IPv4 traffic" meta nfproto ipv6 iifname "tailscale0" counter accept comment "tsconf: accept TS IPv6 traffic" } chain accept_to_tailscale { meta nfproto ipv4 oifname "tailscale0" counter accept comment "tsconf: accept TS IPv4 traffic" meta nfproto ipv6 oifname "tailscale0" counter accept comment "tsconf: accept TS IPv6 traffic" } # # NAT rules # chain dstnat { type nat hook prerouting priority dstnat; policy accept; iifname "eth0" meta l4proto { tcp, udp } th dport domain jump dstnat_lan comment "defconf: handle LAN IPv4 / IPv6 dstnat traffic" } chain srcnat { type nat hook postrouting priority srcnat; policy accept; oifname "eth0" jump srcnat_lan comment "defconf: handle LAN IPv4 / IPv6 srcnat traffic" } chain dstnat_lan { meta nfproto ipv4 meta l4proto { tcp, udp } th dport domain counter redirect to domain comment "lanconf: LAN IPv4 DNS redirect" meta nfproto ipv6 meta l4proto { tcp, udp } th dport domain counter redirect to domain comment "lanconf: LAN IPv6 DNS redirect" } chain srcnat_lan { meta nfproto ipv4 counter masquerade comment "defconf: masquerade LAN IPv4 traffic" } # # Mangle rules # chain mangle_postrouting { type filter hook postrouting priority mangle; policy accept; oifname "eth0" tcp flags syn / fin,syn,rst tcp option maxseg size set rt mtu comment "defconf: zone LAN IPv4 / IPv6 egress MTU fixing" } chain mangle_forward { type filter hook forward priority mangle; policy accept; iifname "eth0" tcp flags syn / fin,syn,rst tcp option maxseg size set rt mtu comment "defconf: zone LAN IPv4 / IPv6 ingress MTU fixing" } }