Ensure nftables Default Deny Firewall Policy

このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。

Description

Base chain policy is the default verdict that will be applied to packets reaching the end of the chain. There are two policies: accept (Default) and drop. If the policy is set to accept, the firewall will accept any packet that is not configured to be denied and the packet will continue traversing the network stack.

Rationale

It is easier to allow acceptable usage than to block unacceptable usage.

Warning

Changing firewall settings while connected over network can result in being locked out of the system.