flush ruleset table inet nodedc_b2_vps { chain input { type filter hook input priority -10; policy drop; iifname "lo" accept ct state invalid drop ct state established,related accept ip protocol icmp accept ip6 nexthdr ipv6-icmp accept tcp dport 22 ct state new limit rate 30/minute burst 60 packets accept tcp dport 9921 ct state new limit rate over 300/second drop tcp dport 9921 accept } chain forward { type filter hook forward priority -10; policy drop; } chain output { type filter hook output priority -10; policy accept; } }