Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You could just set a default deny iptables policy for forwarding to that host, and then explicitly open the ports you want


iptables is legacy now and if you're not already well-versed in it, better go straight to nftables (which should be easier to get started with anyway). On modern systems, iptables commands are translated to nftables equivalents by transitional package.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: