blob: f8e199acdc7129211a709eea655b9186a60b8c61 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
|
<rule family="ip" table="filter" chain="output" handle="35">
<rule_flags>0</rule_flags>
<expr type="payload">
<dreg>1</dreg>
<offset>9</offset>
<len>1</len>
<base>network</base>
</expr>
<expr type="cmp">
<sreg>1</sreg>
<op>eq</op>
<cmpdata>
<data_reg type="value">
<len>1</len>
<data0>0x00000006</data0>
</data_reg>
</cmpdata>
</expr>
<expr type="payload">
<dreg>1</dreg>
<offset>2</offset>
<len>2</len>
<base>transport</base>
</expr>
<expr type="lookup">
<set>map1</set>
<sreg>1</sreg>
<dreg>0</dreg>
</expr>
</rule>
<!-- nft add rule ip filter output tcp dport vmap { 22 => accept, 23 => drop, } -->
|