firewall/zones/prerezotage.nft
2019-04-30 00:12:38 +02:00

31 lines
341 B
Plaintext

#! /sbin/nft -f
table inet firewall {
set allowed_daddr_prerezotage {
type ipv4_addr
flags interval
elements = {
$comnpay,
$website
}
}
chain to_prerezotage {
accept
}
chain from_prerezotage {
ip daddr != @allowed_daddr_prerezotage drop
}
}
table nat {
chain prerezotage_nat {
snat to $ip_self_public
}
}