diff options
| author | Robert Günzler <r@gnzler.io> | 2025-09-07 17:32:13 +0200 |
|---|---|---|
| committer | Robert Günzler <r@gnzler.io> | 2025-09-07 17:42:42 +0200 |
| commit | 38be6c13f76e893cf47636257071b440dec0c5b2 (patch) | |
| tree | f7ded3235a7e3362cbd1ed3d91523968fe0faf90 /bundles/firewall/files/etc/nftables.d/10-tailscale.nft | |
initial commit
Signed-off-by: Robert Günzler <r@gnzler.io>
Diffstat (limited to 'bundles/firewall/files/etc/nftables.d/10-tailscale.nft')
| -rw-r--r-- | bundles/firewall/files/etc/nftables.d/10-tailscale.nft | 16 |
1 files changed, 16 insertions, 0 deletions
diff --git a/bundles/firewall/files/etc/nftables.d/10-tailscale.nft b/bundles/firewall/files/etc/nftables.d/10-tailscale.nft new file mode 100644 index 0000000..f95e142 --- /dev/null +++ b/bundles/firewall/files/etc/nftables.d/10-tailscale.nft @@ -0,0 +1,16 @@ +#!/usr/sbin/nft -f +# vim: set ts=4 sw=4: +table inet filter { + + chain my_filter { + iifname tailscale0 accept \ + comment "Accept inbount tailscale traffic" + + oifname tailscale0 accept \ + comment "Accept outbound tailscale traffic" + + udp dport { 41641 } accept \ + comment "Accept tailscale NAT traffic" + } + +} |