iifname lo accept
jump check-tcp
jump limit-ping
- ct state { established, related } accept
+ ct state established accept
+ ct state related counter accept
jump input-connectivity
ct state invalid counter drop
}
policy drop
oifname lo accept
tcp flags syn tcp option maxseg size set rt mtu
- ct state { established, related } accept
+ ct state established accept
+ ct state related counter accept
jump output-connectivity
}
type filter hook forward priority 0
policy drop
}
+
+ chain prerouting {
+ type filter hook prerouting priority filter
+ policy accept
+ }
}
table inet nat {
chain prerouting {