tmpfs.tech · all tracks · Firewall (nftables)

Accept Related ICMP Errors

Firewall (nftables) · easy · solved in-browser (no VM needed) · 3 tiered hints

Write /etc/nftables.conf with a table inet filter and an input chain (type filter hook input, policy drop). Add one rule that accepts conntrack packets in the established or related states so that ICMP errors and reply traffic for connections you initiated are allowed back in. (Authored config, graded structurally — the engine isn't run here.)

▶ Start this challenge

Nobody has solved this one yet — be the first clear on the leaderboard.

How it works

Open the challenge and an in-page editor appears — write your answer and tmpfs.tech grades it server-side against the same checks a real box would run. No VM, no install, no signup needed to try.

More Firewall (nftables) challenges

Author and reason about nftables rulesets — filtering, NAT and policy.

See all Firewall (nftables) challenges →

FAQ

Is it free? Yes — play as a guest, no signup required to start.

Do I need to install anything? No. Everything runs in your browser.

How is it graded? Automatically and deterministically — your work is checked against the exact rules the live box would apply.