initial commit

This commit is contained in:
2026-08-16 23:16:49 +00:00
commit 2dc83c0626
67 changed files with 1176 additions and 0 deletions
+49
View File
@@ -0,0 +1,49 @@
flowtable ft {
hook ingress priority filter
devices = { eth0, eth1 }
}
chain input {
type filter hook input priority filter; policy drop;
ct state established,related accept
ct state invalid drop
iif lo accept
ip protocol icmp accept
ip6 nexthdr icmpv6 accept
meta mark 0x00000001 accept
iifname eth0 tcp dport 22 accept
iifname eth0.11 tcp dport 22 accept
iifname eth1 udp dport 51820 accept
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } udp dport 53 accept
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } tcp dport 53 accept
iifname eth0.3 udp dport 67 accept
iifname eth1 udp dport 68 accept
#include "/etc/nftables.d/90-input.nft"
}
chain forward {
type filter hook forward priority filter; policy drop;
ct state established,related accept
ct state invalid drop
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 ct state new flow add @ft
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 accept
tcp flags syn tcp option maxseg size set rt mtu
include "/etc/nftables.d/90-forward.nft"
}
chain output {
type route hook output priority filter; policy accept;
#include "/etc/nftables.d/90-output.nft"
}
+9
View File
@@ -0,0 +1,9 @@
chain postrouting {
type nat hook postrouting priority srcnat; policy accept;
oifname eth1 masquerade
}
chain prerouting {
type nat hook prerouting priority dstnat; policy accept;
include "/etc/nftables.d/90-dstnat.nft"
}
+35
View File
@@ -0,0 +1,35 @@
chain vpn_prerouting_dnat {
type nat hook prerouting priority dstnat - 5; policy accept;
iifname wg0 ip daddr 10.250.251.0/24 counter dnat ip prefix to 10.1.0.0/24
iifname wg0 ip daddr 10.250.252.0/24 counter dnat ip prefix to 10.2.0.0/24
iifname wg0 ip daddr 10.250.253.0/24 counter dnat ip prefix to 10.10.0.0/24
iifname wg0 ip daddr 10.250.254.0/24 counter dnat ip prefix to 10.11.0.0/24
iifname wg0 ip daddr 10.250.255.0/24 counter dnat ip prefix to 10.12.0.0/24
iifname wg0 ip daddr 10.250.249.0/24 counter dnat ip prefix to 10.13.0.0/24
}
chain vpn_postrouting_snat {
type nat hook postrouting priority srcnat; policy accept;
oifname wg0 ip saddr 10.1.0.0/24 counter snat ip prefix to 10.250.251.0/24
oifname wg0 ip saddr 10.2.0.0/24 counter snat ip prefix to 10.250.252.0/24
oifname wg0 ip saddr 10.10.0.0/24 counter snat ip prefix to 10.250.253.0/24
oifname wg0 ip saddr 10.11.0.0/24 counter snat ip prefix to 10.250.254.0/24
oifname wg0 ip saddr 10.12.0.0/24 counter snat ip prefix to 10.250.255.0/24
oifname wg0 ip saddr 10.13.0.0/24 counter snat ip prefix to 10.250.249.0/24
}
chain vpn_prerouting_pbr {
type filter hook prerouting priority mangle - 10; policy accept;
iifname wg0 ct state new counter ct mark set 0x000000c7
ip daddr 10.0.0.0/8 return
iifname != "wg0" ct mark 0x000000c7 counter mark set 0x000000c7
}
chain vpn_output_pbr {
type route hook output priority mangle - 10; policy accept;
ct mark 0x000000c7 counter meta mark set 0x000000c7
}
+15
View File
@@ -0,0 +1,15 @@
chain proxy_prerouting {
type filter hook prerouting priority filter - 50; policy accept;
fib daddr type local accept
include "/etc/nftables.d/90-proxy.nft"
}
chain proxy_output {
type route hook output priority mangle; policy accept;
#meta mark 0x000000ff return
#meta l4proto { tcp, udp } ip daddr @cloudflare_ip meta mark set 0x00000001 accept
}
+6
View File
@@ -0,0 +1,6 @@
set private_ip {
type ipv4_addr
flags interval
auto-merge
elements = { 10.0.0.0/8, 100.64.0.0/10, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.0.0.0/24, 192.0.2.0/24, 192.88.99.0/24, 192.168.0.0/16, 198.18.0.0/15, 198.51.100.0/24, 203.0.113.0/24, 224.0.0.0/4, 240.0.0.0/4 }
}
+15
View File
@@ -0,0 +1,15 @@
#!/usr/sbin/nft -f
flush ruleset
table inet filter {
include "/etc/nftables.d/40-sets.nft"
include "/etc/nftables.d/90-sets.nft"
include "/etc/nftables.d/10-filter.nft"
include "/etc/nftables.d/20-vpn.nft"
include "/etc/nftables.d/30-proxy.nft"
}
table ip nat {
include "/etc/nftables.d/10-nat.nft"
}