mirror of
https://github.com/GrapheneOS/infrastructure.git
synced 2025-01-03 11:00:49 -05:00
nftables: friendlier output traffic filtering
This commit is contained in:
parent
3ca0c347c6
commit
e0ab41c4f4
@ -47,6 +47,12 @@ table inet filter {
|
|||||||
|
|
||||||
oif lo accept
|
oif lo accept
|
||||||
|
|
||||||
skuid != {root, systemd-network, chrony, unbound, http, attestation} counter reject
|
skuid != {root, systemd-network, chrony, unbound, http, attestation} counter goto output-reject
|
||||||
|
}
|
||||||
|
|
||||||
|
chain output-reject {
|
||||||
|
meta l4proto udp reject
|
||||||
|
meta l4proto tcp reject with tcp reset
|
||||||
|
reject
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
@ -47,6 +47,12 @@ table inet filter {
|
|||||||
|
|
||||||
oif lo accept
|
oif lo accept
|
||||||
|
|
||||||
skuid != {root, systemd-network, chrony, unbound, http, flarum} counter reject
|
skuid != {root, systemd-network, chrony, unbound, http, flarum} counter goto output-reject
|
||||||
|
}
|
||||||
|
|
||||||
|
chain output-reject {
|
||||||
|
meta l4proto udp reject
|
||||||
|
meta l4proto tcp reject with tcp reset
|
||||||
|
reject
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
@ -50,6 +50,12 @@ table inet filter {
|
|||||||
|
|
||||||
oif lo accept
|
oif lo accept
|
||||||
|
|
||||||
skuid != {root, systemd-network, chrony, unbound, powerdns} counter reject
|
skuid != {root, systemd-network, chrony, unbound, powerdns} counter goto output-reject
|
||||||
|
}
|
||||||
|
|
||||||
|
chain output-reject {
|
||||||
|
meta l4proto udp reject
|
||||||
|
meta l4proto tcp reject with tcp reset
|
||||||
|
reject
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
@ -47,6 +47,12 @@ table inet filter {
|
|||||||
|
|
||||||
oif lo accept
|
oif lo accept
|
||||||
|
|
||||||
skuid != {root, systemd-network, chrony, unbound, postfix, dovecot, dovenull} counter reject
|
skuid != {root, systemd-network, chrony, unbound, postfix, dovecot, dovenull} counter goto output-reject
|
||||||
|
}
|
||||||
|
|
||||||
|
chain output-reject {
|
||||||
|
meta l4proto udp reject
|
||||||
|
meta l4proto tcp reject with tcp reset
|
||||||
|
reject
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
@ -47,6 +47,12 @@ table inet filter {
|
|||||||
|
|
||||||
oif lo accept
|
oif lo accept
|
||||||
|
|
||||||
skuid != {root, systemd-network, chrony, unbound, http, synapse, matterbridge} counter reject
|
skuid != {root, systemd-network, chrony, unbound, http, synapse, matterbridge} counter goto output-reject
|
||||||
|
}
|
||||||
|
|
||||||
|
chain output-reject {
|
||||||
|
meta l4proto udp reject
|
||||||
|
meta l4proto tcp reject with tcp reset
|
||||||
|
reject
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
@ -47,6 +47,12 @@ table inet filter {
|
|||||||
|
|
||||||
oif lo accept
|
oif lo accept
|
||||||
|
|
||||||
skuid != {root, systemd-network, chrony, unbound, http} counter reject
|
skuid != {root, systemd-network, chrony, unbound, http} counter goto output-reject
|
||||||
|
}
|
||||||
|
|
||||||
|
chain output-reject {
|
||||||
|
meta l4proto udp reject
|
||||||
|
meta l4proto tcp reject with tcp reset
|
||||||
|
reject
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
Loading…
Reference in New Issue
Block a user