Firewall (nftables) · medium · live throwaway Linux box · 3 tiered hints
Extend /etc/nftables.conf: define a named set 'blocklist' of ipv4 addresses and an input rule that drops packets whose source is in @blocklist. Keep a base table inet filter / input chain.
▶ Start this challengeNobody has solved this one yet — be the first clear on the leaderboard.
Press start and you get your own real, disposable Linux VM — in the browser terminal or over SSH. Work the task on a live system; tmpfs.tech grades your solution automatically against the actual machine state, then throws the box away. No install, free to try as a guest.
Author and reason about nftables rulesets — filtering, NAT and policy.
See all Firewall (nftables) challenges →
Is it free? Yes — play as a guest, no signup required to start.
Do I need to install anything? No. Everything runs in your browser, or connect over SSH if you prefer your own terminal.
How is it graded? Automatically and deterministically — your work is checked against the real state of the machine you worked on.