Hi,
I wanted to try nftables on Proxmox, it seems quite nicely done, bravo!
I guess most users don't use any output filters, but if using them in iptables, we get a stateful output rule, allowing to only open INPUT for a given port, and assume that it will go out.
Chain PVEFW-HOST-OUT (1...