diff --git a/nftables-discuss.conf b/nftables-discuss.conf index 536e6ae..ec612d8 100644 --- a/nftables-discuss.conf +++ b/nftables-discuss.conf @@ -15,7 +15,7 @@ table inet filter { fib daddr . iif type != { local, broadcast, multicast } counter drop # IPv6 interacts badly with IP-based spam filtering - meta nfproto ipv6 tcp dport {22, 80, 443} reject with tcp reset + meta nfproto ipv6 tcp dport {80, 443} reject with tcp reset tcp dport {22, 80, 443} notrack accept meta l4proto {icmp, ipv6-icmp} notrack accept