Firewall (nftables) · pro · solved in-browser (no VM needed) · 3 tiered hints
Write /etc/nftables.conf with a table inet filter and an input chain (type filter hook input, policy drop). Rate-limit new SSH connections per source address: match `tcp dport 22 ct state new`, then use a dynamic meter keyed by ip saddr — `meter sshflood { ip saddr limit rate over 4/minute }` — and drop packets that exceed the limit. (Authored config, graded structurally — the engine isn't run here.)
▶ Start this challengeNobody has solved this one yet — be the first clear on the leaderboard.
Open the challenge and an in-page editor appears — write your answer and tmpfs.tech grades it server-side against the same checks a real box would run. No VM, no install, no signup needed to try.
Author and reason about nftables rulesets — filtering, NAT and policy.
See all Firewall (nftables) challenges →
Is it free? Yes — play as a guest, no signup required to start.
Do I need to install anything? No. Everything runs in your browser.
How is it graded? Automatically and deterministically — your work is checked against the exact rules the live box would apply.