Blame SPECS/router.nft

Packit c07a97
# Sample configuration snippet for nftables service.
Packit c07a97
# Meant to be included by main.nft, not for direct use.
Packit c07a97
Packit c07a97
# a common table for both IPv4 and IPv6
Packit c07a97
table inet nftables_svc {
Packit c07a97
Packit c07a97
	# base-chain for traffic forwarded by this host
Packit c07a97
	# re-uses 'allow' chain from main.nft
Packit c07a97
	chain FORWARD {
Packit c07a97
		type filter hook forward priority filter + 20
Packit c07a97
		policy accept
Packit c07a97
Packit c07a97
		jump allow
Packit c07a97
		reject with icmpx type host-unreachable
Packit c07a97
	}
Packit c07a97
}