On 11/3/24 21:08, Kerin Millar wrote: [snip]> Upon reading your post a second time, I noticed that your sample ruleset already
contains a rule that depends upon connection tracking. As such, you could use state matching to assist in accounting for backscatter.
[snip] Thanks for the explanations and the NFTables rules. I'll do some more reading and experimenting. /Lars