Don't prevent ICMP replies to go out and only drop TCP and UDP

This commit is contained in:
Tristan PILAT 2020-09-07 11:18:52 +02:00
parent 5f4787d3fd
commit 4781ef509c

View file

@ -322,7 +322,8 @@ fi
## Eventually, we drop the output traffic
$NFT add rule inet minifirewall minifirewall_output ct state established,related accept
$NFT add rule inet minifirewall minifirewall_output drop
$NFT add rule inet minifirewall minifirewall_output meta l4proto udp drop
$NFT add rule inet minifirewall minifirewall_output meta l4proto tcp drop
trap - INT TERM EXIT