add nginx, sshd, ssl roles
This commit is contained in:
@@ -0,0 +1,6 @@
|
||||
set private_ip {
|
||||
type ipv4_addr
|
||||
flags interval
|
||||
auto-merge
|
||||
elements = { 10.0.0.0/8, 100.64.0.0/10, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.0.0.0/24, 192.0.2.0/24, 192.88.99.0/24, 192.168.0.0/16, 198.18.0.0/15, 198.51.100.0/24, 203.0.113.0/24, 224.0.0.0/4, 240.0.0.0/4 }
|
||||
}
|
||||
@@ -0,0 +1,8 @@
|
||||
chain postrouting {
|
||||
type nat hook postrouting priority srcnat; policy accept;
|
||||
oifname eth1 masquerade
|
||||
}
|
||||
chain prerouting {
|
||||
type nat hook prerouting priority dstnat; policy accept;
|
||||
include "/etc/nftables.d/90-dstnat.nft"
|
||||
}
|
||||
@@ -0,0 +1,34 @@
|
||||
flowtable ft {
|
||||
hook ingress priority filter
|
||||
devices = { eth0, eth1 }
|
||||
}
|
||||
chain input {
|
||||
type filter hook input priority filter; policy drop;
|
||||
ct state established,related accept
|
||||
ct state invalid drop
|
||||
iif lo accept
|
||||
meta mark 0x00000001 accept
|
||||
iifname br-eth0 tcp dport 22 accept
|
||||
iifname eth0.11 tcp dport 22 accept
|
||||
iifname tun0 tcp dport 22 accept
|
||||
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } tcp dport 61219 accept
|
||||
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } udp dport 61219 accept
|
||||
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } udp dport 53 accept
|
||||
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } tcp dport 53 accept
|
||||
iifname eth0.3 udp dport 67 accept
|
||||
iifname eth1 udp dport 68 accept
|
||||
include "/etc/nftables.d/90-input.nft"
|
||||
}
|
||||
chain forward {
|
||||
type filter hook forward priority filter; policy drop;
|
||||
ct state established,related accept
|
||||
ct state invalid drop
|
||||
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 ct state new flow add @ft
|
||||
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 accept
|
||||
tcp flags syn tcp option maxseg size set rt mtu
|
||||
include "/etc/nftables.d/90-forward.nft"
|
||||
}
|
||||
chain output {
|
||||
type route hook output priority filter; policy accept;
|
||||
include "/etc/nftables.d/90-output.nft"
|
||||
}
|
||||
@@ -0,0 +1,11 @@
|
||||
chain proxy_prerouting {
|
||||
type filter hook prerouting priority filter - 50; policy accept;
|
||||
fib daddr type local accept
|
||||
meta mark 0x00000001 iif "lo" meta l4proto { tcp, udp } tproxy ip to :61219 counter accept
|
||||
include "/etc/nftables.d/90-proxy-prerouting.nft"
|
||||
}
|
||||
chain proxy_output {
|
||||
type route hook output priority mangle; policy accept;
|
||||
meta mark != 0 return
|
||||
include "/etc/nftables.d/90-proxy-output.nft"
|
||||
}
|
||||
Reference in New Issue
Block a user