nft list ruleset
echo "net.ipv4.ip_forward=1" >> /etc/sysctl.conf
sysctl -p
nft add chain inet filter forward {type filter hook forward priority 0\; policy drop\;}
nft add rule inet filter forward ct state invalid counter drop
nft add rule inet filter forward ct state related,established counter accept
nft add rule inet filter forward iifname "vmbr1" oifname "vmbr0" counter accept
nft add rule inet filter forward tcp dport 22 counter accept
nft chain inet filter forward {policy drop \;}
nft chain inet filter forward {policy accept \;}
chain forward {
type filter hook forward priority filter; policy drop;
ct state invalid counter drop
ct state established,related counter accept
iifname "vmbr1" oifname "vmbr0" counter accept
udp dport 1194 counter accept
tcp dport 22 counter accept
tcp dport { 25, 110, 465, 587, 993 } counter accept
}