#!/usr/sbin/nft -f | |
flush ruleset | |
table inet filter { | |
chain input { | |
type filter hook input priority 0; | |
} | |
chain forward { | |
type filter hook forward priority 0; | |
} | |
chain output { | |
type filter hook output priority 0; | |
} | |
} | |
table ip nat { | |
chain postrouting { | |
type nat hook postrouting priority 100; policy accept; | |
ip saddr SUBNET_CIDR oif "INTERFACE" snat to EDGE_IP | |
} | |
} |