about summary refs log tree commit diff
path: root/bundles/firewall/files/etc/nftables.d/22-ssh.nft
diff options
context:
space:
mode:
Diffstat (limited to 'bundles/firewall/files/etc/nftables.d/22-ssh.nft')
-rw-r--r--bundles/firewall/files/etc/nftables.d/22-ssh.nft10
1 files changed, 10 insertions, 0 deletions
diff --git a/bundles/firewall/files/etc/nftables.d/22-ssh.nft b/bundles/firewall/files/etc/nftables.d/22-ssh.nft
new file mode 100644
index 0000000..c8c91a1
--- /dev/null
+++ b/bundles/firewall/files/etc/nftables.d/22-ssh.nft
@@ -0,0 +1,10 @@
+#!/bin/nft -f
+# vim: set ts=4 sw=4:
+table inet filter {
+
+    chain my_filter {
+        tcp dport { ${node.metadata.get("ssh/port", 22)} } accept \
+        comment "Accept SSH traffic"
+    }
+
+}