mirror of
https://github.com/bol-van/zapret.git
synced 2025-05-24 22:32:58 +03:00
drop time exceeded icmp for nfqws-related connections
This commit is contained in:
@@ -26,7 +26,6 @@ nft add rule inet ztest post meta mark and 0x40000000 == 0 udp dport 443 ct orig
|
||||
sysctl net.netfilter.nf_conntrack_tcp_be_liberal=1
|
||||
nft add chain inet ztest pre "{type filter hook prerouting priority filter;}"
|
||||
nft add rule inet ztest pre tcp sport "{80,443}" ct reply packets 1-3 queue num 200 bypass
|
||||
nft add rule inet ztest pre udp sport 443 ct reply packets 1 queue num 200 bypass
|
||||
|
||||
|
||||
show rules : nft list table inet ztest
|
||||
|
Reference in New Issue
Block a user