Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I would add:

-A PROXY_OUT -d 127.0.0.0/8 -j DROP

-A PROXY_OUT -d 169.254.0.0/16 -j DROP

That seems to cover everything in IPv4, but if you have IPv6 enabled, you probably want fd00::/8, fe80::/10 and ::1/128 as well (disclaimer: my knowledge of IPv6 is rather limited.)



Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: