Alan Orth
9bba0d96bb
I will try using nftables directly instead of via firewalld as of Debian 11 as it is the replacement for the iptables/ipset stack in recent years and is easier to work with. This also includes a systemd service, timer, and script to update the spamhaus DROP lists as nftables sets. Still need to add fail2ban support. |
||
---|---|---|
.. | ||
etc | ||
nftables.conf.j2 | ||
public.xml.j2 | ||
rc.local_Ubuntu.j2 | ||
security.sources.list.j2 | ||
sources.list.j2 | ||
sshd_config_Debian-10.j2 | ||
sshd_config_Debian-11.j2 | ||
sshd_config_Ubuntu-18.04.j2 | ||
sshd_config_Ubuntu-20.04.j2 | ||
sysctl_Debian.j2 | ||
sysctl_Ubuntu.j2 | ||
tarsnap_sources.list.j2 |