::fixture-ready:: $ nft list ruleset table inet filter { chain input { type filter hook input priority 0; policy drop; ct state established,related accept iif "lo" accept tcp dport 22 ip saddr 203.0.113.0/24 accept tcp dport { 80, 443 } accept tcp dport 25 accept tcp dport 5432 drop } } ::exit-code::0 $ nft list ruleset | sed -n '/chain input/,/}/p' chain input { type filter hook input priority 0; policy drop; ct state established,related accept iif "lo" accept tcp dport 22 ip saddr 203.0.113.0/24 accept tcp dport { 80, 443 } accept ::exit-code::0