Firewall (nftables) · easy · solved in-browser (no VM needed) · 3 tiered hints
Write /etc/nftables.conf with a table inet filter and an input chain (type filter hook input). As the first matching behaviour, drop any packet whose conntrack state is invalid (ct state invalid drop) so malformed or out-of-window packets never reach later rules. (Authored config, graded structurally — the engine isn't run here.)
▶ Start this challengeNobody has solved this one yet — be the first clear on the leaderboard.
Open the challenge and an in-page editor appears — write your answer and tmpfs.tech grades it server-side against the same checks a real box would run. No VM, no install, no signup needed to try.
Author and reason about nftables rulesets — filtering, NAT and policy.
See all Firewall (nftables) challenges →
Is it free? Yes — play as a guest, no signup required to start.
Do I need to install anything? No. Everything runs in your browser.
How is it graded? Automatically and deterministically — your work is checked against the exact rules the live box would apply.