#!/bin/bash set -e tmpfile=$(mktemp) if [ ! -w $tmpfile ] ; then echo "Failed to create tmp file" >&2 exit 0 fi trap "rm -rf $tmpfile" EXIT # cleanup if aborted RULESET="table inet filter { chain ssh { type filter hook input priority 0; policy accept; tcp dport ssh accept; } } table inet filter { chain input { type filter hook input priority 1; policy drop; } }" echo "$RULESET" > $tmpfile $NFT -f $tmpfile if [ $? -ne 0 ] ; then echo "E: unable to load good ruleset" >&2 exit 1 fi EXPECTED="table inet filter { chain ssh { type filter hook input priority 0; policy accept; tcp dport ssh accept } chain input { type filter hook input priority 1; policy drop; } }" GET="$($NFT list ruleset)" if [ "$EXPECTED" != "$GET" ] ; then DIFF="$(which diff)" [ -x $DIFF ] && $DIFF -u <(echo "$EXPECTED") <(echo "$GET") exit 1 fi