tmpfs.tech · all tracks · Firewall (nftables)

Drop Invalid Conntrack Early

Firewall (nftables) · easy · solved in-browser (no VM needed) · 3 tiered hints

Write /etc/nftables.conf with a table inet filter and an input chain (type filter hook input). As the first matching behaviour, drop any packet whose conntrack state is invalid (ct state invalid drop) so malformed or out-of-window packets never reach later rules. (Authored config, graded structurally — the engine isn't run here.)

▶ Start this challenge

Nobody has solved this one yet — be the first clear on the leaderboard.

How it works

Open the challenge and an in-page editor appears — write your answer and tmpfs.tech grades it server-side against the same checks a real box would run. No VM, no install, no signup needed to try.

More Firewall (nftables) challenges

Author and reason about nftables rulesets — filtering, NAT and policy.

See all Firewall (nftables) challenges →

FAQ

Is it free? Yes — play as a guest, no signup required to start.

Do I need to install anything? No. Everything runs in your browser.

How is it graded? Automatically and deterministically — your work is checked against the exact rules the live box would apply.