#!/usr/sbin/nft -f # van-router NAT — masquerade LAN out whatever the WAN of the moment is # (anything that is NOT the LAN bridge br0: ethernet/Starlink, wifi, future 4G) table ip van_router_nat delete table ip van_router_nat table ip van_router_nat { chain postrouting { type nat hook postrouting priority srcnat; policy accept; ip saddr 10.42.0.0/24 oifname != "br0" masquerade } }