https://medium.com/@diyar.parwana/nf...e-d13c5f0cf40f

If the server is not used as router or gateway, we can have the policy drop for it.
sudo nft add chain inet filter forward { type filter hook forward priority filter \; policy drop \; }