2022-12-18 13:46:03 +01:00
|
|
|
nft -f - <<__EOF
|
|
|
|
table bridge filter {
|
|
|
|
chain MULTICAST_OUT {
|
|
|
|
# Erlaube DHCP Requests
|
|
|
|
# -p IPv4 --ip-proto udp --ip-dport 67 -j RETURN
|
|
|
|
ether type ip udp dport 67 counter return
|
|
|
|
}
|
2016-04-05 21:56:45 +02:00
|
|
|
|
2022-12-18 13:46:03 +01:00
|
|
|
chain FORWARD {
|
|
|
|
# Erlaube nur DHCP Request von CLIENT -> BATMAN
|
|
|
|
# -p IPv4 --ip-proto udp --ip-dport 67 -j OUT_ONLY
|
|
|
|
ether type ip udp dport 67 counter jump OUT_ONLY
|
2016-04-05 21:56:45 +02:00
|
|
|
|
2022-12-18 13:46:03 +01:00
|
|
|
# Erlaube nur DHCP Antworten von BATMAN -> CLIENT
|
|
|
|
# -p IPv4 --ip-proto udp --ip-dport 68 -j IN_ONLY
|
|
|
|
ether type ip udp dport 68 counter jump IN_ONLY
|
|
|
|
}
|
|
|
|
}
|
|
|
|
__EOF
|