nft list ruleset
echo "net.ipv4.ip_forward=1" >> /etc/sysctl.conf
sysctl -p
nft add chain inet filter forward {type filter hook forward priority 0\; policy drop\;}
nft add rule inet filter forward ct state invalid counter drop
nft add rule inet filter forward ct state related,established counter accept
nft add rule inet filter forward iifname "vmbr1" oifname "vmbr0" counter accept
nft add rule inet filter forward tcp dport 22 counter accept
nft chain inet filter forward {policy drop \;}
nft chain inet filter forward {policy accept \;}
chain forward { type filter hook forward priority filter; policy drop; ct state invalid counter drop ct state established,related counter accept iifname "vmbr1" oifname "vmbr0" counter accept udp dport 1194 counter accept tcp dport 22 counter accept tcp dport { 25, 110, 465, 587, 993 } counter accept }