-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathnftables.nft
More file actions
122 lines (92 loc) · 2.74 KB
/
Copy pathnftables.nft
File metadata and controls
122 lines (92 loc) · 2.74 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
#!/usr/sbin/nft -f
#
# Assumptions:
# WAN = ppp0
# LAN = br0
# LAN subnet = 192.168.88.0/24
# Tailscale = sing-box built-in endpoint
# Tailscale UDP listen_port = 41641
#
# Important:
# Load nftables BEFORE sing-box.
# Because this file uses "flush ruleset", reloading it while sing-box
# auto_redirect is running will remove sing-box's dynamically-created
# nftables rules. Restart sing-box after reloading this file.
#
flush ruleset
define WAN_IF = "ppp0"
define LAN_IF = "br0"
define LAN_NET = 192.168.88.0/24
define TAILSCALE_PORT = 41641
include "/etc/nftables.d/*.conf"
table inet firewall {
#
# INPUT
# Traffic destined to the router itself
#
chain input {
type filter hook input priority filter; policy drop;
# Drop invalid packets
ct state invalid drop
# Loopback
iifname "lo" accept
# Established / related traffic
ct state established,related accept
# Trust LAN access to the router
iifname $LAN_IF accept
# ICMP / PMTU / diagnostics
ip protocol icmp accept
meta nfproto ipv6 meta l4proto ipv6-icmp accept
# sing-box built-in Tailscale endpoint
iifname $WAN_IF udp dport $TAILSCALE_PORT accept
# Everything else from WAN is dropped by policy
}
#
# FORWARD
# Routed traffic through this router
#
chain forward {
type filter hook forward priority filter; policy drop;
# Drop invalid packets
ct state invalid drop
# Return traffic
ct state established,related accept
# LAN -> WAN
# This includes CN-IP traffic bypassed by sing-box
iifname $LAN_IF oifname $WAN_IF accept
# WAN -> LAN only when NAT/DNAT mapping exists
# Needed for Full Cone UDP inbound mappings
iifname $WAN_IF oifname $LAN_IF ct status dnat accept
}
#
# OUTPUT
# Traffic generated by the router itself
#
chain output {
type filter hook output priority filter; policy accept;
}
#
# DNAT / Full Cone inbound
#
chain dstnat {
type nat hook prerouting priority dstnat; policy accept;
iifname $WAN_IF jump dstnat_wan
}
chain dstnat_wan {
# Full Cone UDP inbound lookup
meta nfproto ipv4 meta l4proto udp fullcone
}
#
# SNAT / Full Cone outbound
#
chain srcnat {
type nat hook postrouting priority srcnat; policy accept;
oifname $WAN_IF jump srcnat_wan
}
chain srcnat_wan {
# Native / bypassed LAN UDP -> Full Cone NAT
ip saddr $LAN_NET meta l4proto udp fullcone
# TCP and all other IPv4 traffic -> normal dynamic NAT
ip saddr $LAN_NET masquerade
}
}