a772f7a5d4
Installs nftables config useful for pmOS:: 1) drop all connections to wwan* (wildcard matching supported, are there any other wwan iface names that wouldn't match this?) 2) allow ssh, drop from wwan (kinda redundant w/ the first rule, but doesn't hurt..), allow DHCP on usb* 3) allow all incoming connections on usb* (with the -openusb subpackage) 4) enable logging all nftable events (with the -log subpackage), very useful for debugging fixes #1024
13 lines
217 B
Text
13 lines
217 B
Text
#!/usr/sbin/nft -f
|
|
|
|
# Allow all traffic from usb-ethernet interfaces for debugging
|
|
# and porting.
|
|
|
|
table inet filter {
|
|
chain input {
|
|
|
|
# allow all from USB net
|
|
iifname "usb*" accept comment "accept USB net"
|
|
|
|
}
|
|
}
|