diff --git a/minifirewall-start.sh b/minifirewall-start.sh index 66776da..aa95502 100755 --- a/minifirewall-start.sh +++ b/minifirewall-start.sh @@ -322,7 +322,8 @@ fi ## Eventually, we drop the output traffic $NFT add rule inet minifirewall minifirewall_output ct state established,related accept -$NFT add rule inet minifirewall minifirewall_output drop +$NFT add rule inet minifirewall minifirewall_output meta l4proto udp drop +$NFT add rule inet minifirewall minifirewall_output meta l4proto tcp drop trap - INT TERM EXIT