table inet firewall { define tcp_ports = {80, 443} chain inbound { type filter hook input priority 0; policy drop; tcp dport { $tcp_ports } ct state new accept } }