saved a few lines in named set definitons
This commit is contained in:
parent
359a43654a
commit
7398a5046b
12
filter.nft
12
filter.nft
|
@ -6,8 +6,7 @@ include "/var/geoipsets/dbip/nftset/ipv4/*.ipv4"
|
||||||
|
|
||||||
table ip filter {
|
table ip filter {
|
||||||
set allowed_tcp_ports {
|
set allowed_tcp_ports {
|
||||||
type inet_service;
|
type inet_service; flags constant;
|
||||||
flags constant;
|
|
||||||
elements = {
|
elements = {
|
||||||
$SSH_PORT1, $SSH_PORT2, $DNS_PORT, $HTTP_PORT, $HTTPS_PORT, $SYNCPLAY_PORT,
|
$SSH_PORT1, $SSH_PORT2, $DNS_PORT, $HTTP_PORT, $HTTPS_PORT, $SYNCPLAY_PORT,
|
||||||
$TERRARIA_PORT, $OPENTTD_PORT, $MAINPAGE_PORT, $NEXTCLOUD_PORT, $GITEA_PORT,
|
$TERRARIA_PORT, $OPENTTD_PORT, $MAINPAGE_PORT, $NEXTCLOUD_PORT, $GITEA_PORT,
|
||||||
|
@ -16,20 +15,17 @@ table ip filter {
|
||||||
}
|
}
|
||||||
|
|
||||||
set allowed_udp_ports_in {
|
set allowed_udp_ports_in {
|
||||||
type inet_service;
|
type inet_service; flags constant;
|
||||||
flags constant;
|
|
||||||
elements = { $DNS_PORT, $DHCP_IN_PORT, $OPENVPN_PORT, $FACTORIO_PORT, $OPENTTD_PORT, $CSTRIKE_PORT, $SNMP_POLL_PORT, $SNMP_TRAP_PORT }
|
elements = { $DNS_PORT, $DHCP_IN_PORT, $OPENVPN_PORT, $FACTORIO_PORT, $OPENTTD_PORT, $CSTRIKE_PORT, $SNMP_POLL_PORT, $SNMP_TRAP_PORT }
|
||||||
}
|
}
|
||||||
|
|
||||||
set allowed_udp_ports_out {
|
set allowed_udp_ports_out {
|
||||||
type inet_service;
|
type inet_service; flags constant;
|
||||||
flags constant;
|
|
||||||
elements = { $DNS_PORT, $DHCP_OUT_PORT, $SNMP_POLL_PORT }
|
elements = { $DNS_PORT, $DHCP_OUT_PORT, $SNMP_POLL_PORT }
|
||||||
}
|
}
|
||||||
|
|
||||||
set ipv4_geo_blacklist {
|
set ipv4_geo_blacklist {
|
||||||
type ipv4_addr;
|
type ipv4_addr; flags interval;
|
||||||
flags interval;
|
|
||||||
elements = { };
|
elements = { };
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
Loading…
Reference in New Issue