浏览代码

nftables: Ignore packets for UDP port 0

Signed-off-by: Maximilian Wilhelm <max@sdn.clinic>
Maximilian Wilhelm 2 年之前
父节点
当前提交
ea33ab41c8
共有 1 个文件被更改,包括 1 次插入0 次删除
  1. 1 0
      nftables/nftables.conf.tmpl

+ 1 - 0
nftables/nftables.conf.tmpl

@@ -34,6 +34,7 @@ table ip filter {
 		type filter hook input priority 0; policy drop;
 		iifname "lo" counter accept
 		ip protocol icmp counter jump icmp_chain
+		udp dport 0 counter drop
 		tcp dport 7 counter drop comment "Ignore echo protocol queries"
 		ct state invalid counter drop
 		counter jump admin_access