about summary refs log tree commit diff
path: root/bundles/firewall/files/etc/nftables.nft
diff options
context:
space:
mode:
Diffstat (limited to 'bundles/firewall/files/etc/nftables.nft')
-rw-r--r--bundles/firewall/files/etc/nftables.nft21
1 files changed, 21 insertions, 0 deletions
diff --git a/bundles/firewall/files/etc/nftables.nft b/bundles/firewall/files/etc/nftables.nft
new file mode 100644
index 0000000..35b10dd
--- /dev/null
+++ b/bundles/firewall/files/etc/nftables.nft
@@ -0,0 +1,21 @@
+#!/usr/sbin/nft -f
+# vim: set ts=4 sw=4:
+# You can find examples in /usr/share/nftables/.
+
+# Clear all prior state
+flush ruleset
+
+# Basic IPv4/IPv6 stateful firewall for server/workstation.
+table inet filter {
+
+	chain input   { type filter hook input priority 0;   policy drop; }
+	chain forward { type filter hook forward priority 0; policy drop; }
+	chain output  { type filter hook output priority 0;  policy accept; }
+
+}
+
+# The state of stateful objects saved on the nftables service stop.
+include "/var/lib/nftables/*.nft"
+
+# Rules
+include "/etc/nftables.d/*.nft"