@company на @client.
ssh <dstIP> убедитесь в доступности SSH‑соединения с company на client
[root@company ~]# ssh 10.0.12.1
The authenticity of host '10.0.12.1 (10.0.12.1)' can't be established.
ED25519 key fingerprint is SHA256:BxaYoHAW5ddfM6EwmgSAZ2tKXCH0zoppLfEcQ8YiGdg.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '10.0.12.1' (ED25519) to the list of known hosts.
Last login: Sun Oct 19 13:19:43 2025
[root@client ~]#
<^D>logout
Connection to 10.0.12.1 closed.
[root@company ~]#
systemctl enable --now nftables.service запустите сервис поддержки сетевого экрана на network.
nft add rule inet filter forward ip protocol tcp reject установите блокировку TCP‑соединений в сети
[root@network ~]# systemctl enable --now nftables.serviceCreated symlink '/etc/systemd/system/multi-user.target.wants/nftables.service' -> '/usr/lib/systemd/system/nftables.service'.[root@network ~]# nft add rule inet filter forward ip protocol tcp reject[root@network ~]#
ssh <dstIP> убедитесь в недоступности SSH‑соединения с company на client
[root@company ~]# ssh 10.0.12.1
ssh: connect to host 10.0.12.1 port 22: Connection refused
[root@company ~]#
Примечание