From 509e328c03c41b6db326a352d46af91d2e45f28b Mon Sep 17 00:00:00 2001 From: CallMeR <9463297+callmer@user.noreply.gitee.com> Date: Fri, 18 Apr 2025 09:57:03 +0800 Subject: [PATCH] =?UTF-8?q?=E6=9B=B4=E6=96=B0=20TS=20=E9=98=B2=E7=81=AB?= =?UTF-8?q?=E5=A2=99?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- src/debian/debian_ts_nftables.conf | 15 ++++++++------- 1 file changed, 8 insertions(+), 7 deletions(-) diff --git a/src/debian/debian_ts_nftables.conf b/src/debian/debian_ts_nftables.conf index 7534136..47179d3 100644 --- a/src/debian/debian_ts_nftables.conf +++ b/src/debian/debian_ts_nftables.conf @@ -25,31 +25,32 @@ table inet router { chain input { type filter hook input priority filter; policy drop; - ct state established,related accept comment "defconf: handle inbound flows" iif "lo" accept comment "defconf: accept traffic from loopback" + ct state vmap { established : accept, related : accept } comment "defconf: handle inbound flows" + tcp flags & (fin | syn | rst | ack) == syn jump syn_flood comment "defconf: rate limit new TCP connections" iifname "eth0" jump input_lan comment "defconf: handle LAN IPv4 / IPv6 input traffic" iifname "tailscale0" jump input_tailscale comment "tsconf: handle TS IPv4 / IPv6 input traffic" } chain forward { type filter hook forward priority filter; policy drop; - ct state established,related goto handle_offload comment "defconf: handle forwarded flows" - ct state invalid counter drop comment "defconf: drop packets in invalid flow state" + ct state established,related flow add @ft; + ct state vmap { established : accept, related : accept } comment "defconf: handle forwarded flows" iifname "eth0" jump forward_lan comment "defconf: handle LAN IPv4 / IPv6 forward traffic" iifname "tailscale0" jump forward_tailscale comment "tsconf: handle TS IPv4 / IPv6 forward traffic" } chain output { type filter hook output priority filter; policy accept; - ct state established,related accept comment "defconf: handle outbound flows" oif "lo" accept comment "defconf: accept traffic towards loopback" + ct state vmap { established : accept, related : accept } comment "defconf: handle outbound flows" oifname "eth0" jump output_lan comment "defconf: handle LAN IPv4 / IPv6 output traffic" oifname "tailscale0" jump output_tailscale comment "tsconf: handle TS IPv4 / IPv6 output traffic" } - chain handle_offload { - flow add @ft accept comment "defconf: track forwarded flows" - accept + chain syn_flood { + limit rate 50/second burst 100 packets return comment "defconf: accept new TCP connections below rate-limit" + counter drop comment "defconf: drop excess new TCP connections" } chain input_lan {