Don't prevent ICMP replies to go out and only drop TCP and UDP
This commit is contained in:
parent
5f4787d3fd
commit
4781ef509c
|
@ -322,7 +322,8 @@ fi
|
|||
|
||||
## Eventually, we drop the output traffic
|
||||
$NFT add rule inet minifirewall minifirewall_output ct state established,related accept
|
||||
$NFT add rule inet minifirewall minifirewall_output drop
|
||||
$NFT add rule inet minifirewall minifirewall_output meta l4proto udp drop
|
||||
$NFT add rule inet minifirewall minifirewall_output meta l4proto tcp drop
|
||||
|
||||
trap - INT TERM EXIT
|
||||
|
||||
|
|
Loading…
Reference in a new issue