20bcecbcec
- Add IPv6 ip6tables rules to prevent IPv6 traffic leaks (forwarding was enabled but only IPv4 masquerade existed) - Tighten FORWARD chain: only allow wg0→internet and established return, instead of blanket ACCEPT from wg0 - Scope NAT masquerade to VPN subnet only - Block VPN clients from server-local services (SSH/80/443) via INPUT rules - Set UFW DEFAULT_FORWARD_POLICY=ACCEPT (required for VPN routing; base hardening sets default deny which blocks forwarded packets) - Add SaveConfig = false to prevent runtime state overwriting config - Add reload ufw handler Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>