pmaports/main/postmarketos-config-nftables/rules/01_wwan.nft
Clayton Craft a772f7a5d4
postmarketos-config-nftables: add package for configuring nftables fw (MR 2060)
Installs nftables config useful for pmOS::

1) drop all connections to wwan* (wildcard matching supported, are there
   any other wwan iface names that wouldn't match this?)

2) allow ssh, drop from wwan (kinda redundant w/ the first rule, but
   doesn't hurt..), allow DHCP on usb*

3) allow all incoming connections on usb* (with the -openusb subpackage)

4) enable logging all nftable events (with the -log subpackage), very
   useful for debugging

fixes #1024
2021-06-14 13:29:34 -07:00

10 lines
166 B
Text

#!/usr/sbin/nft -f
table inet filter {
chain input {
# drop all incoming connections on wwan
iifname "wwan*" drop comment "drop all connections on wwan"
}
}