table ip mangle { chain FORWARD { type filter hook forward priority mangle; policy accept; } } # Warning: table ip nat is managed by iptables-nft, do not touch! table ip nat { chain PREROUTING { type nat hook prerouting priority dstnat; policy accept; xt match "addrtype" counter packets 12072 bytes 4564241 jump DOCKER } chain OUTPUT { type nat hook output priority dstnat; policy accept; ip daddr != 127.0.0.0/8 xt match "addrtype" counter packets 1854 bytes 111240 jump DOCKER } chain POSTROUTING { type nat hook postrouting priority srcnat; policy accept; ip saddr 172.17.0.0/16 oifname != "docker0" counter packets 903 bytes 61577 xt target "MASQUERADE" ip saddr 172.21.0.0/16 oifname != "br-86a5d6b30e2b" counter packets 344 bytes 27744 xt target "MASQUERADE" ip saddr 172.25.0.0/16 oifname != "br-61495e14a004" counter packets 374 bytes 33016 xt target "MASQUERADE" ip saddr 172.30.0.0/16 oifname != "br-5107796ee9b4" counter packets 352 bytes 28224 xt target "MASQUERADE" ip saddr 172.18.0.0/16 oifname != "br-cfd337ac4e58" counter packets 339 bytes 27444 xt target "MASQUERADE" ip saddr 172.19.0.0/16 oifname != "br-8f0c6ee01425" counter packets 351 bytes 28164 xt target "MASQUERADE" ip saddr 172.22.0.0/16 oifname != "br-75ac3c36e87f" counter packets 333 bytes 27084 xt target "MASQUERADE" ip saddr 172.20.0.0/16 oifname != "br-0529801521bc" counter packets 343 bytes 27404 xt target "MASQUERADE" } chain DOCKER { iifname != "br-61495e14a004" tcp dport 5680 counter packets 2 bytes 120 xt target "DNAT" ip daddr 127.0.0.1 iifname != "br-61495e14a004" tcp dport 15673 counter packets 0 bytes 0 xt target "DNAT" ip daddr 127.0.0.1 iifname != "docker0" tcp dport 55432 counter packets 0 bytes 0 xt target "DNAT" } } # Warning: table ip filter is managed by iptables-nft, do not touch! table ip filter { chain DOCKER-FORWARD { counter packets 702328 bytes 1801910999 jump DOCKER-CT counter packets 337315 bytes 23928864 jump DOCKER-INTERNAL counter packets 337315 bytes 23928864 jump DOCKER-BRIDGE iifname "br-75ac3c36e87f" counter packets 0 bytes 0 accept iifname "br-86a5d6b30e2b" counter packets 0 bytes 0 accept iifname "br-8f0c6ee01425" counter packets 0 bytes 0 accept iifname "br-cfd337ac4e58" counter packets 0 bytes 0 accept iifname "br-0529801521bc" counter packets 0 bytes 0 accept iifname "br-5107796ee9b4" counter packets 0 bytes 0 accept iifname "br-61495e14a004" counter packets 0 bytes 0 accept iifname "docker0" counter packets 337315 bytes 23928864 accept } chain FORWARD { type filter hook forward priority filter; policy drop; counter packets 702328 bytes 1801910999 jump DOCKER-USER counter packets 702328 bytes 1801910999 jump DOCKER-FORWARD } chain DOCKER-USER { ip protocol tcp counter packets 702510 bytes 1801965868 jump f2b-sshd oifname "incusbr0" counter packets 0 bytes 0 accept iifname "incusbr0" counter packets 0 bytes 0 accept } chain f2b-sshd { counter packets 10423854 bytes 13891318049 return } chain INPUT { type filter hook input priority filter; policy accept; ip protocol tcp counter packets 9721344 bytes 12089352181 jump f2b-sshd } chain DOCKER { ip daddr 172.17.0.2 iifname != "docker0" oifname "docker0" tcp dport 5432 counter packets 0 bytes 0 accept ip daddr 172.25.0.2 iifname != "br-61495e14a004" oifname "br-61495e14a004" tcp dport 15672 counter packets 0 bytes 0 accept ip daddr 172.25.0.2 iifname != "br-61495e14a004" oifname "br-61495e14a004" tcp dport 5672 counter packets 0 bytes 0 accept iifname != "br-75ac3c36e87f" oifname "br-75ac3c36e87f" counter packets 0 bytes 0 drop iifname != "br-86a5d6b30e2b" oifname "br-86a5d6b30e2b" counter packets 0 bytes 0 drop iifname != "br-8f0c6ee01425" oifname "br-8f0c6ee01425" counter packets 0 bytes 0 drop iifname != "br-cfd337ac4e58" oifname "br-cfd337ac4e58" counter packets 0 bytes 0 drop iifname != "br-0529801521bc" oifname "br-0529801521bc" counter packets 0 bytes 0 drop iifname != "br-5107796ee9b4" oifname "br-5107796ee9b4" counter packets 0 bytes 0 drop iifname != "br-61495e14a004" oifname "br-61495e14a004" counter packets 0 bytes 0 drop iifname != "docker0" oifname "docker0" counter packets 0 bytes 0 drop } chain DOCKER-BRIDGE { oifname "br-75ac3c36e87f" counter packets 0 bytes 0 jump DOCKER oifname "br-86a5d6b30e2b" counter packets 0 bytes 0 jump DOCKER oifname "br-8f0c6ee01425" counter packets 0 bytes 0 jump DOCKER oifname "br-cfd337ac4e58" counter packets 0 bytes 0 jump DOCKER oifname "br-0529801521bc" counter packets 0 bytes 0 jump DOCKER oifname "br-5107796ee9b4" counter packets 0 bytes 0 jump DOCKER oifname "br-61495e14a004" counter packets 0 bytes 0 jump DOCKER oifname "docker0" counter packets 0 bytes 0 jump DOCKER } chain DOCKER-CT { oifname "br-75ac3c36e87f" xt match "conntrack" counter packets 0 bytes 0 accept oifname "br-86a5d6b30e2b" xt match "conntrack" counter packets 0 bytes 0 accept oifname "br-8f0c6ee01425" xt match "conntrack" counter packets 0 bytes 0 accept oifname "br-cfd337ac4e58" xt match "conntrack" counter packets 0 bytes 0 accept oifname "br-0529801521bc" xt match "conntrack" counter packets 0 bytes 0 accept oifname "br-5107796ee9b4" xt match "conntrack" counter packets 0 bytes 0 accept oifname "br-61495e14a004" xt match "conntrack" counter packets 0 bytes 0 accept oifname "docker0" xt match "conntrack" counter packets 365013 bytes 1777982135 accept } chain DOCKER-INTERNAL { } } # Warning: table ip6 nat is managed by iptables-nft, do not touch! table ip6 nat { chain PREROUTING { type nat hook prerouting priority dstnat; policy accept; xt match "addrtype" counter packets 363 bytes 67927 jump DOCKER } chain OUTPUT { type nat hook output priority dstnat; policy accept; ip6 daddr != ::1 xt match "addrtype" counter packets 0 bytes 0 jump DOCKER } chain DOCKER { } } table ip6 filter { chain DOCKER-FORWARD { counter packets 0 bytes 0 jump DOCKER-CT counter packets 0 bytes 0 jump DOCKER-INTERNAL counter packets 0 bytes 0 jump DOCKER-BRIDGE } chain FORWARD { type filter hook forward priority filter; policy accept; counter packets 0 bytes 0 jump DOCKER-USER counter packets 0 bytes 0 jump DOCKER-FORWARD } chain DOCKER-USER { } chain DOCKER { } chain DOCKER-BRIDGE { } chain DOCKER-CT { } chain DOCKER-INTERNAL { } } table ip raw { chain PREROUTING { type filter hook prerouting priority raw; policy accept; ip daddr 172.25.0.2 iifname != "br-61495e14a004" counter packets 0 bytes 0 drop ip daddr 127.0.0.1 iifname != "lo" tcp dport 15673 counter packets 0 bytes 0 drop ip daddr 172.17.0.2 iifname != "docker0" counter packets 0 bytes 0 drop ip daddr 127.0.0.1 iifname != "lo" tcp dport 55432 counter packets 0 bytes 0 drop } } table inet incus { set bridges { type ifname elements = { "incusbr0" } } chain pstrt.incusbr0 { type nat hook postrouting priority srcnat; policy accept; ip saddr 10.7.169.0/24 oifname @bridges accept ip saddr 10.7.169.0/24 ip daddr != 10.7.169.0/24 masquerade ip6 saddr fd42:cbc4:e123:f6::/64 oifname @bridges accept ip6 saddr fd42:cbc4:e123:f6::/64 ip6 daddr != fd42:cbc4:e123:f6::/64 masquerade } chain fwd.incusbr0 { type filter hook forward priority filter; policy accept; ip version 4 oifname "incusbr0" accept ip version 4 iifname "incusbr0" accept ip6 version 6 oifname "incusbr0" accept ip6 version 6 iifname "incusbr0" accept } chain in.incusbr0 { type filter hook input priority filter; policy accept; iifname "incusbr0" tcp dport 53 accept iifname "incusbr0" udp dport 53 accept iifname "incusbr0" icmp type { destination-unreachable, time-exceeded, parameter-problem } accept iifname "incusbr0" udp dport 67 accept iifname "incusbr0" ip protocol udp udp checksum set 0 iifname "incusbr0" icmpv6 type { destination-unreachable, packet-too-big, time-exceeded, parameter-problem, nd-router-solicit, nd-neighbor-solicit, nd-neighbor-advert, mld2-listener-report } accept iifname "incusbr0" udp dport 547 accept } chain out.incusbr0 { type filter hook output priority filter; policy accept; oifname "incusbr0" tcp sport 53 accept oifname "incusbr0" udp sport 53 accept oifname "incusbr0" icmp type { destination-unreachable, time-exceeded, parameter-problem } accept oifname "incusbr0" udp sport 67 accept oifname "incusbr0" ip protocol udp udp checksum set 0 oifname "incusbr0" icmpv6 type { destination-unreachable, packet-too-big, time-exceeded, parameter-problem, echo-request, nd-router-advert, nd-neighbor-solicit, nd-neighbor-advert, mld2-listener-report } accept oifname "incusbr0" udp sport 547 accept } } table ip fct_filter { chain OUTPUT { type filter hook output priority filter; policy accept; } chain FCT-QUARANTINE-EMS { } chain FCT-QUARANTINE-FAZ { } chain FORWARD { type filter hook forward priority filter; policy accept; } chain FCT-WEBFILTER-QUIC-CHAIN { } chain INPUT { type filter hook input priority filter; policy accept; } chain FCT-QUARANTINE { } chain FCT-DNS-QUIC-FILTER { } chain FCT-VPN-CHAIN { } } table ip fct_nat { chain OUTPUT { type nat hook output priority dstnat; policy accept; } chain FCT-DNS-UDP-CHAIN-STAGE-2 { } chain FCT-DNS-UDP-CHAIN-STAGE-1 { } chain FCT-TCP-CHAIN { } chain FCT-DNS-DOH-CHAIN-STAGE-1 { } chain FCT-WEBFILTER-CHAIN { } chain FCT-DNS-DOH-CHAIN-STAGE-2 { } } table ip6 fct_filter { chain FCT-QUARANTINE { } chain INPUT { type filter hook input priority filter; policy accept; } chain FORWARD { type filter hook forward priority filter; policy accept; } chain OUTPUT { type filter hook output priority filter; policy accept; } } table ip fct_mangle { chain PREROUTING { type filter hook prerouting priority mangle; policy accept; } chain FCT-UDP-STAGE-1 { } chain OUTPUT { type route hook output priority mangle; policy accept; } chain FCT-UDP-STAGE-2 { } chain FCT-UDP-OUTPUT { } } table inet mesh { chain input { type filter hook input priority filter; policy drop; ct state established,related accept ct state invalid drop iif "lo" accept iifname != { "mesh0", "wlp3s0" } accept icmp type echo-request accept icmpv6 type { echo-request, nd-router-advert, nd-neighbor-solicit, nd-neighbor-advert } accept iifname != { "mesh0", "wlp3s0" } udp dport { 53, 67 } accept iifname != { "mesh0", "wlp3s0" } tcp dport 53 accept ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 22 accept tcp dport 22 accept ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 53 accept ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } udp dport 53 accept } chain output { type filter hook output priority filter; policy accept; } chain forward { type filter hook forward priority filter; policy drop; ct state established,related accept ct state invalid drop iifname != { "mesh0", "wlp3s0" } accept iifname "mesh0" oifname "mesh0" accept ct original proto-dst 22 accept ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 53 accept ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 53 accept } }