FirewallPF · default-deny · kill switch
PROTECTED
Default profile: inbound deny · outbound usable
Inbound: drop, no exposed services (always) · Outbound: accept out of the box (so apt and the browser work) · tunnel-only egress kill switch available as an OPT-IN profile, armed only when wg0/tun0 is detected · antispoof · fail-closed (fallback table if the main ruleset fails to load)
nftables ACTIVE
Active rules (nftables) — view of the opt-in kill-switch profile
ActionDirProtoPortSource → DestinationHits
PASSoutudp51820wg0 → VPN tunnel (if configured)22.7k
PASSouttcp853→ encrypted DNS (DoT, Quad9)9.1k
PASSanyanylo (loopback)
PASSin/outanywg0 (inside the tunnel)48.2k
BLOCKinany** → host1.2k
BLOCKoutany*outside the tunnel (kill switch)340
DEMO mode · no persistence · read-only sandbox · no real actions · © Copyright Ferran Suils