diff --git a/sisr1/tp07/files_firewall/current_ruleset_v1.nft b/sisr1/tp07/files_firewall/current_ruleset_v1.nft index 5e456c3..3e35f9b 100644 --- a/sisr1/tp07/files_firewall/current_ruleset_v1.nft +++ b/sisr1/tp07/files_firewall/current_ruleset_v1.nft @@ -1,13 +1,17 @@ +define netif = enp0s3 +define dmzif = enp0s8 +define lanif = enp0s9 + table ip ipfilter { chain routing { type filter hook forward priority filter; policy accept; - icmp type echo-request iif { "enp0s3", "enp0s8" } drop + icmp type echo-request iif { $netif, $dmzif } drop icmp type { echo-reply, echo-request } accept drop } chain system_in { type filter hook input priority filter; policy accept; - icmp type echo-request iif { "enp0s3", "enp0s8" } drop + icmp type echo-request iif { $netif, $dmzif } drop } }