diff --git a/roulette.nft b/roulette.nft index 47fe87d..6a4ef6e 100644 --- a/roulette.nft +++ b/roulette.nft @@ -19,9 +19,17 @@ table inet firewall { set ip_roulette { type ipv4_addr } + set allowed_roulette { + type ipv4_addr + elements = { + 10.7.0.4, + 92.242.132.24 + } + } + chain roulette { - ip saddr @ip_roulette ip daddr != 92.242.132.24 drop - ip daddr @ip_roulette ip saddr != 92.242.132.24 drop + ip saddr @ip_roulette ip daddr != @allowed_roulette drop + ip daddr @ip_roulette ip saddr != @allowed_roulette drop } }