diff options
Diffstat (limited to 'test/example_config/wg0/nftables.conf')
-rw-r--r-- | test/example_config/wg0/nftables.conf | 33 |
1 files changed, 33 insertions, 0 deletions
diff --git a/test/example_config/wg0/nftables.conf b/test/example_config/wg0/nftables.conf new file mode 100644 index 0000000..2b9762d --- /dev/null +++ b/test/example_config/wg0/nftables.conf @@ -0,0 +1,33 @@ +table ip wg0 { + chain preraw { + type filter hook prerouting priority raw; policy accept; + iifname != "wg0" ip daddr 10.55.127.342 fib saddr type != local drop; + } + + chain premangle { + type filter hook prerouting priority mangle; policy accept; + meta l4proto udp meta mark set ct mark; + } + + chain postmangle { + type filter hook postrouting priority mangle; policy accept; + meta l4proto udp meta mark 0xa22a61a9 ct mark set meta mark; + } +} + +table ip6 wg0 { + chain preraw { + type filter hook prerouting priority raw; policy accept; + iifname != "wg0" ip6 daddr ab00:aaaa:aaa:aa02::5:abcd fib saddr type != local drop; + } + + chain premangle { + type filter hook prerouting priority mangle; policy accept; + meta l4proto udp meta mark set ct mark; + } + + chain postmangle { + type filter hook postrouting priority mangle; policy accept; + meta l4proto udp meta mark 0xa22a61a9 ct mark set meta mark; + } +} |