mirror of
https://github.com/C24Be/AS_Network_List.git
synced 2026-05-13 19:41:12 +03:00
25 lines
719 B
Plaintext
25 lines
719 B
Plaintext
# Autogenerated nftables blacklist
|
|
# Generated: 2026-05-12T08:30:42.373743Z
|
|
# Empty input produced no prefixes
|
|
# IPv4: 0, IPv6: 0
|
|
#
|
|
# Usage:
|
|
# sudo nft -f <this-file>
|
|
# # VK egress blocking for VPN clients via NAT/FORWARD
|
|
# sudo nft add chain inet filter forward '{ type filter hook forward priority 0; policy accept; }'
|
|
# sudo nft add rule inet filter forward iifname "<VPN_IFACE>" ip daddr @blacklist_vk_v4 counter reject
|
|
# sudo nft add rule inet filter forward iifname "<VPN_IFACE>" ip6 daddr @blacklist_vk_v6 counter reject
|
|
|
|
table inet filter {
|
|
|
|
set blacklist_vk_v4 {
|
|
type ipv4_addr
|
|
flags interval
|
|
}
|
|
|
|
set blacklist_vk_v6 {
|
|
type ipv6_addr
|
|
flags interval
|
|
}
|
|
|
|
} |