feat(security): added nftables firewall

This commit is contained in:
NaeiKinDus 2023-12-12 00:00:00 +00:00
parent 7e617bc471
commit 639b01c351
Signed by: WoodSmellParticle
GPG key ID: 8E52ADFF7CA8AE56
9 changed files with 211 additions and 0 deletions

View file

@ -21,3 +21,14 @@ custom_common:
force_sign: true
signing_key: "{{ vault_common_gitconfig_signingkey }}"
install_fonts: true
custom_security:
firewall:
filter:
policy:
output: accept
forward: accept
mangle:
drop_privatenets: false
policy:
forward: accept