Hacker News new | ask | show | jobs
by RunningDroid 1433 days ago
That's basically what I do, nftables is configured to drop most* incoming traffic unless it's coming from wg0.

*: with the exception of wireguard's ports, transmission's non-admin ports, etc