ruleset = ''
table inet filter {
chain input-lan {
- meta l4proto { udp, tcp } th dport domain counter accept comment "DNS"
- meta l4proto { udp, tcp } th dport bootps counter accept comment "DHCP"
tcp dport ssh counter accept comment "SSH"
udp dport 60000-61000 counter accept comment "Mosh"
tcp dport 5201 counter accept comment "iperf"
chain output-lan {
tcp dport { ssh, 2222 } counter accept comment "SSH"
- counter accept
tcp dport 5201 counter accept comment "iperf"
}
chain output-net {