1[Unit]
2Description=IPERF3 Server
3
4[Service]
5ExecStart=/usr/bin/iperf3 -s
6#Hardening
7PrivateTmp=true
8ProtectSystem=strict
9ProtectHome=true
10ProtectKernelModules=true
11ProtectKernelTunables=true
12ProtectControlGroups=true
13MountFlags=private
14NoNewPrivileges=true
15PrivateDevices=true
16RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX
17MemoryDenyWriteExecute=true
18DynamicUser=true
19
20[Install]
21WantedBy=multi-user.target
22